Techstrong TV – April 11, 2024
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Happy Thursday, everyone. We've got a lot of AI stuff to go over with you, as well as some news on the security bloggers network, security creators Network, RSA, all of this and more you are watching Techron Gang. Hi everyone, happy Thursday.
It's Alan Shimmel here, uh, CEO and, uh, Textron. And you're watching the Textron Gang. As I mentioned.
Let me tell you what gang members we've got on for today. First of all, as usual, joining us from, uh, high up in the Rocky Mountains. It's our CTO and principal research analyst, Mitchell.
Ashley. Hey, Mitch. Welcome.
Happy Thursday. What a great day. Happy Thursday to you joining a, a Roving gang member joining us from the Raleigh Durham Triangle area.
I think if he's home. Anyway, our AI expert, mark Hinkle. Hey, mark, welcome.
Thanks Alan. And I am home for once. Good, good for you.
I'm glad you made it home. Um, and then joining me here in our Boca Raton Headquarters Studios, our Echo Insights editor and lady about town, Bonnie Schneider. Hi, Bonnie.
Hi, Alan. Great to be here. Thanks to have you here.
So guys, let's just jump into stuff today. ai site, and it's, it's basically a welcome or acknowledging, I think, I don't know if a welcome's the right word, acknowledging, uh, that we are entering the generative AI election era as if our elections didn't have enough aggravation before AI with meddling and social media and fake news and everything else. Now we've got AI to crank it up.
Mark, you're the AI guy. What do you, what do you think It's gonna be a wild ride? Um, you know, in the last three months, it seems like every day there's some kind of new AI model that does text to video.
They're getting better. Um, they're, you know, we are gonna have to have a real critical eye for this election and for the news in general going forward. It's just the barrier to creating realistic beat fakes and videos in.
Now, you know, voice cloning has gotten really, really good too. I think it's a matter of security for everyone from phishing schemes to, you know, news misinformation based on generative AI being, you know, so good so fast. Yeah.
Yeah. I see. I already see the AI out there in terms of bots, like bots, anytime, um, someone posts something political on, on social media, it'll be followed by lots of, um, I think bot accounts, because if you look, they have very few followers and they're influencing, or they're disrupting.
They're, they're designed to make people argue with each other on social media. So we're seeing that now, and I think because it is an election year, this is only gonna escalate. And as, as Mark mentioned, those DeepFakes, I mean, they're pretty convincing.
Now, some of them, especially if you're not paying attention, you think it is, um, a candidate or someone that's running. So messaging and AI's influence on messaging is gonna be something to watch. Absolutely.
You know, putting the election stuff aside for a second, I still read another article today about a, a pretty widespread problem we're having in high schools and colleges, and that is with deep fakes of like fake nude shots of, of especially of, of women girls, right. That, uh, using ai, you know, it's, it's the cool thing to kind of make, make AI images fake images of, you know, women's faces or girls in school's faces on, on kind of pornographic bodies or nude bodies doing pornographic things, you know, and, and that's not new. Of course, people have been Photoshopping and playing that game, but AI, of course, takes that to a whole nother level.
The, to me, that, and what we're talking about with the election stuff really points to the same issue we've been having now since kind of the rise of social media. And that is that as a body politic, as a civilization, we can't discern truth from fiction and with AI and bots and, and, and the bots really are there to game the system, right? Because the way these algorithms work, the more, excuse me, the more likes or comments or particular posts gets, the higher up its visibility, the more it trends.
And our system is based on that. The whole social media kind of algorithm is based on that. And, and, you know, people are gaming it.
I, I mean, I was on a podcast a couple of weeks ago for not here on Techstrong. Someone had invited me on their podcast, and when it was published, they asked me to put it on LinkedIn because they have a cadre of followers who will like it and share it and push it to help gain the LinkedIn algorithm. And I get it.
You want, you want to get your stuff out there, but this is, this is the world we live in, and now you add AI to the mix that's like turbocharging that kind of activity. And I, Yeah, I think it's taken to another level, right? Yeah.
I, I, I can't imagine as, as Mark said right off the bat, it's trouble, it's trouble. How are we, how how's the average person supposed to get their information and ascertain truth from fiction here? You know, the head headline grabbing stuff, you know, you talk about the deep fakes and people putting images, people's faces on images, et cetera.
Those are the things that are, are easy to at least talk about maybe getting more challenging to spot. What I think is, is interesting is both everyone who's doing creative writing of some type is, is using generative AI as a tool in that process. I mean, 'cause they wanna learn it usually, but also it's an aid in doing that.
I, I'm interested in, in how you could take generative AI and both craft multiple prompts for a particular topic or article, but then, and then create your own echo chamber where you could be reposting and having generative AI create, create 25 different ways of reposting the following article. And you could do that through an API and you can do that through posting on multiple accounts. So we could see a real escalation of the number of kind of fake posts that are happening and some real manipulation taking that, you know, gaming the, the system up.
I think another level, I, I absolutely, I, you know, so what, what's the answer here though? Where, where's the light at the end of the tunnel tunnel? Or are we just all, Well, there's definitely talk, obviously of, of some regulation, but you're right, it is already a problem.
And, um, it isn't easy to tell what's true and what isn't. I think that the, the, because going back to the fact that it's an election year, I think that the, those, those fake accounts and, um, the superficial ones are gonna be, um, watched even further. And who knows?
I mean, if it gets to the point where it gets, let's say, where it really causes a, a, a widespread misinformation event that that'll just put more spotlight on it. But I, I think, I think it, like, it's gonna just go upwards in terms of attention and an escalation. And, um, the bots that I mentioned straight into November, I, I think it's already caused the widespread.
I think if you go back to the 2016 presidential election, that was Trump and Clinton, Hillary Clinton, you know, the, the Russian meddling, right? Using, and that was before AI per se, but the Russian meddling using fake accounts and, and trying to gain the algorithms that we've seen absolutely had a, a, a impact in that election. And I think also what I forget the name now, of the British firm that was hired by one of the candidates, um, Cambridge Analytic, Cambridge Analytics, that's it, mark.
Um, and that was before they had generator AI as a tool. Imagine, you know, a Cambridge analytics type of operation now, a generate armed with gen AI type of functionality. I, I don't know, do you put a total ban on, on political ads and, and commentary?
How, how are people supposed to get their information and how would, how sophisticated did they have to be to separate, you know, truth from fiction here? I I, I, I'm at a loss. I, you know, I hate to be pessimistic, but I'm at, I, I don't know what to say.
Well, I, There is legislation, I think introduced by Holly and Koons, if I remember right. Um, protect elections from AI or deceptive ai. I don't know if that'll go anywhere, but even if it does, you know, that's never stopped.
The, the ransomware dudes and everybody else doing things That shouldnt be guns only gun only outlaws have guns. Yeah, exactly. But I think that particular AI law was more to stop sort of robocall with fake voices, You know, this was deep fakes.
Yeah, yeah, yeah. I think it was prompted by that robocall that Mark, you were gonna say something? Yeah, I think actually you started out, I think you have part of the answer already.
And I think that when you, like you're talking about the security bloggers network and the security creators is, I think that we, in the short term, it's gonna be a mess. In the longer term, I think we start to have more of a relationship with individual news reporters. So I feel like, you know, I see the Creator newsletter economy, some of it's gamed, all of it's always gonna be gamed.
But I look at like Matt tbi, who was, you know, a respected journalist and then did the Twitter files, and now he has racket news. And I feel like in the long term, the transparency is hard for a big corporation and for a smaller person who's staking their career on their integrity, you know, I think more of these citizen journalists are what they called them 20 some years ago, and now we call them creators, but they're sensationalists. But I also think there's a lot of folks out there that are, you know, gonna make their bones on being good journalists and citizen journalists instead of, you know, part of the big media conglomerates that, you know, 80% of our news is paid for right now by big pharma.
I mean, that's, that's part of the, the, the whole problem is that the, the model isn't a meritocracy. You know, w William Morris is turning over in his grave right now going, this Is, well, it's definitely a rise of independent journalists for sure. Um, and that keeps on growing, um, as well.
But what's interesting with the ai, another way the AI influences us, is it also kind of keeps us within our own ecosystem. Like, it, it knows tribe you like tribe tribes, right? Which isn't good because it's, it's, it's better if people are with opposing ideas, get to debate them rather than just be with Somebody, raise with you.
But I, I think what we have found is that people want to get their own views amplified. Yeah. So they tend to stay in a tribe where their own world views are amplified and, And validated.
Right. And other people believe like I do. Yep.
And I, I, and you know, I've read articles where this is translating for, like, for some of the first time in the US anyway, to people picking where they wanna live, right? They, they wanna live in a red state or a blue state, but not just at the state level. They wanna be in a neighborhood.
How did that neighborhood vote? Wow. What's the political, I have no idea what my neighborhood vote.
Yeah. You know, and, and it's, there's been a bunch of articles. 500,000 people have moved outta Florida in the last, I think two years.
Many more have moved in, but for the people moved out, one of the big things in addition of cost of living insurance was the, the, the political hate, if you will, uh, among the populace here. And it, it, again, you've got, if you've got actors who want to play that out and heighten the, the, you know, the, the divide and, and try to sway elections and stuff, this is a great tool for them. And I don't know, I don't know how you could stop them from using it.
So anyway, make good choices. Dig into the information you're looking at. You know, democracy depends on free and fair elections, and, um, I think it's all of our duty to, to, you know, make sure we're, we're not being fooled.
And then, by the way, it's not just a US issue. You're seeing this in every, in every democracy and, and, and, and non democracies worldwide. So anyway, let's hope we figure out a solution to this sooner than later.
We're gonna take a break on Textron gang. We'll be right back. com is the number one online destination for DevOps education and community building.
com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more. com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com, where the world meets DevOps. Hey, everyone, we're back here on Text Gang. Our next subject, again is AI related, and, but it, we're getting away from the politics and the doom and gloom.
It's, can organizations afford LLM? So maybe it is doom and gloom. Um, you know, we've spent a lot of time recently here on the gang and on our tech strong sites talking about, you know, will as, as this whole AI thing unfolds, we're learning not all LLMs are created equal.
And some LLMs and some s SLMs will be better for certain jobs. And it's about using the right tool for the job. And, and in this case, that tool is an LLM, but you know, we, we talk like LLMs are something you could go in the candy store and buy in a baseball card pack with a pack with a little piece of bubble gum.
No, there's more to an LLM than that, I think. Um, and can the organizations who are gonna rely on these LLMs actually afford to sort of do the customization work that's really going to, you know, give them the ultimate value there? So Mark, what do you think?
Yeah, I think you have to break it down into a couple different categories. So the, the thing that is the most resource intensive with LLMs is training it on your data and training is, is taking an algorithm and using machine learning to populate that LLM. Those are the things that like OpenAI is doing that generates those sensational power usage stats.
Then when you and I use Google Gemini or chat CPT, it's doing something called inference. And the inference is less CPU intensive. So what isn't practical for a lot of organizations is the training.
So that's when you download what's called a foundational model. Like, uh, um, meta Has Llama or Mistral is another, um, popular vendor of these sort of open access or open source models. And then those things don't take as much, but it's like everything in technology, the more that we, it's available, the more we consume.
It's that way, you know, the amount that we drove our cars versus in the twenties has gone up substantially. The amount that we use our desktop computers and our smartphones continue to use to rise and the amount that we use ai. So, um, I think the, the takeaway is this is LLMs are easily accessible.
The compute that underlies them is what's expensive. So that's the, the Nvidia GPUs that's, um, Brock with a, uh, queue is another vendor there. There's a ton, ton of up and comers there that are all going to, um, have this problem to solve, is how can they reduce the amount of power they consume while they're producing more and more inference, and in some cases, training Fair Barney?
Well, Uh, uh, we were talking about cast ai, and they have a new product that's optimizing this, um, which is interesting because when I was looking into it, um, the, the, the, the pitch is, well, it's more cost effective, but there's also a sustainability angle. Because if they're optimizing cost and they're using, um, less energy, they're also freeing up the, um, ability to focus on other products and other things at the same time. So it's, it's I guess the cast ai, um, point is that it's cost effective, but I was thinking that, um, if if they're optimizing it, then it's gonna be using less energy, and that's, you know, beneficial to sustainability.
But that's just maybe in the smaller picture of that product. Well, part of it is they, what CAST has done, to your point, is they've added the AI aspect to running on, uh, Kubernetes, which they already monitor to Kubernetes and cloud environments. And I guess this is gonna be offered as part of Google, uh, GCP initially, but it's, it's kind of the larger finops of managing costs.
Um, I, I'm curious, I, I'm doubtful that they're gonna recommend different, uh, LLMs for the one that you're using. Maybe they will, but that seems to be such a fast changing landscape. And I wonder too, you know, I'm thinking we want to be flexible and don't get too tied into a single LLM, but Mark, once you've trained, if you've trained data into an LLM, you're not gonna be punting and going somewhere else, are you?
No. I mean, you, you may have a foundational model that you actually access data through a Vector database, and that makes it sort of portable, but they're not so much portable. I think it's more like a dashboard approach.
But if we look, and I was an early cloud guy. I mean, Apache Cloud Stack was one of the early and open stack cloud providers, and we've talked about, you know, this arbitrage of cloud forever and ever. And what happens is that people do not, you know, dynamically switch workloads.
It just, they just keep an eye on the cost. There's, there's been tons, you know, NetApp has SPOT IBM has cost optimization tools. There's a lot of these tools, but they're not, no one has sort of cracked that code in cloud, and there's not a whole lot of difference in AI other than it's a different workload you're monitoring.
So, and then you, you, you really have to take this holistically as, you know, we talked a little earlier in the show about, you know, power consumption versus cost now, you know, and then the amount of work, how do we measure work if it's inference versus training? So I think it's, it's a pretty complex thing to crack. Um, it's good to know what your costs are, but at the end of the day, the, the sort of core services just like storage when Amazon and Google and compute, that's a race to zero.
And I mean, it's a commoditization play in the long term, hopefully given once we get past the GP shortage. Yeah. Um, you know, also, I would be remiss not to say that a Google Cloud next is going on right now out in Vegas.
Mike Ard, our chief content officer, is not on the gang today. I was hoping to have a live report from him at Google, Google Cloud, but I don't know if we're gonna pull that off. But they touted it a bunch of, uh, new AI advances too around this.
Do you see us moving to a place where different LLMs are available in a marketplace, if you will. Right? And, and you could kind sass your LLM, if you will, right?
You don't have to buy it, you just rent it. And maybe it has, you know, it's trained a certain way, or it's trained for healthcare, it's trained for finance, it's trained for pharma, or what have you. And this way the, the amount of investment in time and resources that an organization would need to put in to have, you know, a specialized LLM might be more affordable, might be easier, you know, more fungible.
Yeah. That's cast announcement came from, um, Las Vegas, uh, yesterday. Yep.
Sorry, Mitch, go ahead. So Martin's gonna talk, go ahead, Mike. Yeah, so the thing that they are doing right now, there's two things, is what we're seeing is these models that are called mixture of experts, which nails what Alan is saying.
So it has this routing layer that says what expert is the best for this? So if Bonnie has a climate change question, or Alan has a question about, you know, style or whatever, it's gonna route the best expert. But in the long term, what I think we're gonna see is this gateway.
And so, uh, Kong, which is a big, uh, gateway provider for regular data, has just released an open source gateway that's gonna say exactly what you did is depending on your use case. So we may have what I call our general LLM, the Google of L lms, maybe it's Chachi, bt, and then we're gonna have, you know, med GPT and we're gonna have lawyer GPT, and we're gonna have those things. And you're gonna have these gateways, I believe, that'll route your questions to some, you know, maybe not a marketplace, but pre-approved like model.
So you may have an internal model for the tech strong gang that has your internal dialogue versus us asking general election questions of Chachi, BT or Gemini, or someone like that. Fair enough. I mean, we, we will have to see how that, you know, makes its way to market.
Uh, you know, again, I I we're so early in the gen AI story, so, you know, can organizations of afford LLMs talk to me in two, three years? And I'll, I'll have a much better handle on that. And, and, and your, you know, opinion.
I, I think we're in such a rapidly evolving, changing cycle right now that what's, you know, prohibitively expensive today, is affordable tomorrow. And, and what's affordable today is, is is quite likely commodity tomorrow. Right?
And, and, you know, and what's the, what's open source gonna have, uh, uh, play a role in here, in, in keeping, you know, that whole ecosystem open and, and somewhat affordable? Hopefully. Um, you know, Alan, I feel like we're living in a, a giant experiment, which is, you know, every piece of software that I use has some kind of an AI element to it.
Most of 'em want charge you nine bucks a month or whatever it is, right? I can't afford to do it on all of them, but most of them, you know, since it's in software, they can tell if you copy it or you click copy button or you do a thumbs up. So it's kind of got this built in training, almost like we would train, uh, through some ML algorithms to start to learn what are useful uses of Gen ai.
Just sticking it on your email client doesn't make it a better email client, right? Sticking in front of a database of documents, well, might be helpful, might not, but we're, we're kinda learn, as you mentioned, we're early, but we're also learning in real time what's useful. And people that get really smart about how their technology is being used, I think are gonna have a leg up.
The great, I, I don't, you know, I, I absolutely agree with you there, Mitchell. It's, I gotta tell you though, first I thought you were gonna tell me that we're all living in some AI matrix or something, right? Red pill.
You Were, you were thinking I was going matrix, I was going red pill, blue Pillers already, you know? But, um, We are batteries, but that's another topic. Mm-Hmm.
Just, just a little data point to that, to your point, Alan, of like, I remember getting on the internet in the late eighties, and if you had a T three at your office that was super fast, that was 44 megabits per second. Today, 25 years later, I have a gigabit, which is to my home fiber, to the home that's consumer. Uh, T one back or T three, back in those days, cost tens upon tens of thousands Of no, T three was about 40, 40 to $50,000.
Yeah. 45 grand. Yeah, it's five.
If it was five grand a month, five to 10, depending on where you are. Yeah. Yeah.
Today I have for a hundred dollars a month or less, I have, you know, 20 times the bandwidth that, or, you know, less than, you know, like 1% of the cost. So that's, I mean, I think, You know how Tech Knowledge works, right? So now all of the apps you use require 10 times the bandwidth to really use them well.
Yeah. And, you know, you wanna watch that video in HDR or just plain old fashioned hd. Yeah.
Um, so, you know, there, there, there's that, there's that and it, and it is, I, I see it in my house as well. Um, it, it does kind of freak me out. com era company called Inter Reliant.
And we were buying, uh, T three and T one lines from WorldCom, if you remember, back in WorldCom. And then this company outta Houston came to us and said, oh, we, we could arbitrage your, your, uh, bandwidth costs and we can be a better bandwidth provider provider for you. So I went down with the CEO of my company and our VP of, uh, I-C-T-E-O to Houston and this big building with a big E in front of it, and, um, went all the way up to the top floor.
And, you know, I remember they gave us a whole pitch on, on Bandwidth Media and arbitrage. And I asked my CEO, 'cause I, I was younger then, I'm a little more naive. I said, herb, is this real?
What do you think? He said, these guys are either the biggest geniuses in the world, or they're crooks. Well, it was RO and they were crooks.
Um, so, you know, who knows what, what, what the future holds when it comes to these things, but it, it, it certainly is there. Anyway, we're gonna take a break here on, uh, Textron Gang. We're back with our third block it.
We're gonna move off AI a little bit to security, so stay tuned. All right. We're back here on Techstrong Gang.
Our last block today is something that's very personal to me. Um, we recently put out a press release and a blog I'm writing should be out by the time. This is, uh, on Techstrong TV that we have renamed the Security Bloggers Network.
The Security Creators Network. And this year at the RSA conference, instead of doing our usual security bloggers meetup, we're actually gonna do the Security Creators meetup. What does that all mean?
Well, let me give you a little history in the genesis of the Security bloggers network and, and Mitch Mitchell. Ashley, by the way, was right at my side when all of this happened so he could verify. What I'm telling you is, is the truth.
Um, I was, Mitchell and I had helped co-found a company called Still Secure Back in the early two thousands, 2000, 2001. And the, uh, uh, VC behind that was our good friend Brad felt Brad was investing in many companies back then as the whole Web two oh thing was really starting to kick in. And, uh, Brad invite introduced me to a fellow named Dick Costolo.
Dick at the time was the founder of a company called Feed Burner out of Chicago. Dick went on to become the CEO of Twitter, but at the time, he was the founder, CEO of Feed Burner. And also at that time, the world of the RSS kinda syndication, really simple syndication was like the tower of Ba Babel.
There were multiple standards of RSS, much like SBOs and stuff like that today. And just because you were able to render one version of RSS didn't mean you could read other RSS versions. What FeedBurner did was standardize the RSS feeds.
So no matter whether you were using R rss, one r, SS two Adam, or any of the others, if you used FeedBurner, your, your blog or whatever you were using to syndicate displayed correctly, it was great. What a great concept, what great technology, but how did you make money from it? And so, Dick Costo had this great idea of if he could bundle like-minded blogs on, you know, similar topics, he could then sell advertising into that syndicated feed.
Excuse me. And so Dick asked, well, Brad Feld put together the, the VC bloggers network. He asked me to put together a security bloggers network.
I still secure was a security company. So I reached out to a couple of my friends and I did that. And as I said, this is about, oh, it's almost 20 years ago now.
And, uh, we, we put it together pretty quickly. We probably had 50 to a hundred security blogs syndicated in there. And, um, this is around, as I say, 2003, 2004.
Um, and then we decide, wow, you know, and the security bloggers world was happening at the time. There were, Martin McKay had the network security blog. Mike Rothman, security Insight, rich Mogul Securosis, um, uh, Bruce Schneider was, was blogging of course.
Probably the biggest one was Brian Krebs, our friend Brian. Well, Brian was still, I think at the Washington Post at the time. He was, yeah.
But, um, anyway, we quickly gathered this community that, that in retrospect was like a who's who of of bloggers. And we decided, you know what, it's time we meet in person. Let's, let's grab some beers at RSA this year.
And we, we put it out there that, you know, everyone who blocks security is invited to this bloggers meetup. And before you know it, companies are reaching out saying, Hey, I heard about this. We'd like to sponsor it.
We'll buy your beer for you. You don't have to ask me twice. Um, so we had the very first bloggers meet up, I, I guess it was either 2004 or 2005, I don't remember now.
There were probably about 35 or 40 of us that got together. And, um, you know, that, that's where it was born. From there, the Security bloggers network quickly grew to over 400 security blogs.
'cause blogging became very popular. And the security bloggers meetup became an annual mainstay event at RSA, where those core people. And it grew, I think at the biggest, we probably had 250 people at the party.
Those core people. It was the best of event of RSA week. It was a marketing free zone, no sales zone, chill out, talk to your security friends and, you know, and have some fun, good, good drink, good food, good people.
Um, fast forward, and by the way, Dick Costal Law then sold a feed burner to Google for like 80 or $90 million on like zero revenue. Um, crazy story, but true. About six months later, I get a call from Google and they said, Hey, Dick Costolo gave us your name.
You know, we, we own FeedBurner now. We don't know what to do with the security bloggers network. Would you take it back?
I said, sure. You know, I, I, I created it. I'm happy to.
And I took it back. This was probably 2006 or 2007, and at that point, I, I put the security bloggers network feed, which was just a syndicated RSS feed out into the wild. Anyone could use it, republish it, do whatever.
Um, but I always thought it was a tremendous, tremendous, uh, uh, you know, a a a re reservoir of information. What a great resource. com launches March of 2014.
Within a year, I'm thinking, what's the next site we should do? Well, I'm a security guy. I, I want to do security.
And we come up with the notion of Security Boulevard. But what made Security Boulevard special is I took that security bloggers network feed and made it the backbone of Security Boulevard. So today there's still, I think 300 or 350 blogs in the security bloggers network publishing anywhere from 20 to 40 articles a day on, on Security Boulevard.
And it's why we have probably the most content of any site out there when it comes to security. Um, and it, and it's, it's real. And it has been a long time, and thank you to every single person who's ever been a member of the security Bloggers network.
But, you know, times change, times change. First of all, not everyone blogs today, we have people who do podcasts and videos and newsletters, and, uh, they create content on TikTok and social media. They create tech, uh, content for tech vendors like White Papers and eBooks and infographs and any number of things.
So calling it the Bloggers Network was kind of old. And speaking of old the last couple years, even during covid, when, when RSA was open, the last two years, we, we had our bloggers network and it was great. 'cause our core people, about 75 to a hundred of them still come down.
We love getting together, but we've been doing this for 20 years, and many of us have been in the industry much longer than that. We wanna bring in fresh blood, we want new people, we want new security content creators to be part of this, to, to take the baton, to take the torch and carry it forward. So, long story short, that was a very long story, and it wasn't very short.
But the, the, we've renamed the Security Bloggers Network as the Security Creators Network, still the same great blogs that were there before you could still join. And if you publish any kind of security, you can, uh, security content you can apply to have that added to the Security Boulevard site. And for RSA this year, as we do every year, the Wednesday night of RSA, this year it's March 8th, we are having the very first Security Creators network meet up, um, May 8th, uh, May 8th, excuse me, not March 8th.
Yes. And, uh, it's at the Tonga room, which we're also kind of building on the old Tonga Con, uh, vibe that Jack Daniels and, and some of those folks put together. And a shout out to Jack.
I don't think he'll be at RSA this year. Um, but anyway, you're all invited. You could look at, at the websites, you could Google it as a Eventbrite page.
Love to have you there. We are looking for sponsors, as we always do for the Security Creators Network. This isn't a moneymaking thing for Techstrong.
We, we throw money into, it's just, it is still the same old story. We're covering the beers. So if, if you're interested in that, reach out to me as well.
But that, that's Mitch, did I miss anything? No, I love to hear you recant the story. And I've heard it many times, you know, which is on, and I love hearing it.
What's amazing to me is I think the spirit of what started it was a group of us saying, we need to, we're getting in security. We gotta share this information, right? We're all kind of battling the same wars and trying to figure out similar stuff.
And we can go to RSA and listen to each other's talks. But, you know, we're, we're blogging now, let's put this together. And it was a pretty altruistic, you know, community-based thing.
And I think that community is still, is what's really held it together. Yes, it's great content, it's great people, but it's, it's both collaborating together and sharing that which is what the network is, and expanding that to podcasts and videos and, and newsletters and all different kinds of content, um, just makes it a wider audience. And frankly, I mean, one of the benefits to you and I was, that also helped our, our profile in the industry.
Oh, Absolutely. Increasing that. I mean, mm-Hmm.
And people are doing that today. That's one of the inspirations for doing a podcast or, you know, doing these kinds of activities. So we encourage you to join.
We would love to have you, uh, be part of the network. Yep. Two things I I left out there.
I do wanna mention, one of the things that made the Bloggers Network Meetup, uh, pretty cool was we used to do the security bloggers awards. And I always thought they were tongue in cheek, but a lot of people took 'em very seriously. We wanted to do it again for this year, but we're not gonna have, we didn't have enough runway between getting the, a place, the Tonga room and doing everything.
But next year we will be back with a vengeance and we will be doing the Security Creators Network awards. And then lastly, and maybe most importantly, as I said, this isn't a text strong only thing. So I reached out to my friend Gianna, who is with the, or runs the security marketing professionals or cyber security Marketing Professional society, and they are partnering with us on this and producing it.
Gianna and her team will help a lot with it. And don't be fooled because they're the marketing people that this is now becoming a marketing heavy event. It's not, it's still a no marketing zone, but they have great connections into people creating security content today.
And they also have a lot of people kind of coming up in the ranks. And I think they're a great organization for us to partner with to revitalize the, the meetup and, and bring new blood in. I mean, we, we want to see new people come have some drinks on us.
Yeah. I think it'd be worth, and I know you can't name everybody, but there's some folks like Jennifer and people like that Who are Yeah. Pe part of, yeah.
People who are instrumental and, you know, my, our good friend Jennifer Gio, media fighter, we quite frankly, Mike Rothman, rich Mogul, and I wrote her coattails for 10 years making this party. Jennifer did the whole thing. Uh, but Mike Rothman, rich Mogul, I think I met, mentioned Martin McKay and Bruce Schneider and, and Brian Krebs.
People like Graham Cluey though, um, Troy Hunter from Microsoft always won a lot of awards. Uh, you know, Andy Ellis, Jack Daniels, I mentioned, um, just trying to think of Jeremiah Grossman, Robert Hansen, ARS Snake, I just a who's who of security, you know, that we saw Chris Hoff. Mm-Hmm.
The Hoffmeister right. Early on. Chris was, was huge in that.
He was one of the best bloggers out there. Um, so many more. Alex Hutton, I, I could probably go on forever there.
There's actually a Facebook page, uh, security bloggers meetup where you can see pictures. I happen to look at it yesterday to make the event bright. I've got pictures down there from 2007 to eight.
I had so much hair. Um, but anyway, um, do check it out if you're, if you're a cyber professional, if you create content around security, be part of it. That's my public service announcement for today.
Anything else? Well, I think it's really timely that you changed the name I blog. When I think of blogs, I do think of the early two thousands.
Yeah. And everybody had a blog. So content creation creator network is great.
And I also wanna point out kind of connecting it to our early segment about AI and how we don't know what's true and what's, what's real. Because we're all just virtual and online. I think it's terrific that you're doing this in person event where the people that you, you read their blog, you don't really know them.
And then you get to meet face to face. Absolutely. What an excellent opportunity.
And I will tell you the network that was built through this, I, I don't mean the, the bloggers network, I mean, the personal networking that goes on has really fueled, it's fueled tech strong. It's fueled my career. It's fueled Mitchell's career.
A lot of 'em are really great friends. And some of 'em we only see once a year at RSA at the meetup and others, you know, we're, we're working with or, or talking to all the time. But it is a big part of not only our network, but just our colleagues and friends that we've had for so many years.
Yep. The labor of love. Alright, I think that's gonna wrap our Textron gang today.
I was, I'm sorry I was a little subdued there for a while, but whatever. Um, I thought you were gonna get emotional there for Them. I, I was holding back.
It's a nice Story. Um, but it is, it's a true story. Anyway, we have a great lineup of Textron TV besides on the gang today.
Mark, thanks for joining us. Hey man. I, I know we're getting, we're about a month, well, a little more than a month out on, on the AI event.
You wanna give a quick update? Yeah, yeah. So we have the Artificially Intelligent Enterprise Conference going on online, May 21st.
We're adding folks from Amazon. We're adding folks from the practitioners that were at large banks. They're talking about how to use generative AI from a firsthand experience.
So, uh, if you get a chance, uh, go to, uh, tech Strong events, check us out, sign up. Um, it should be a good event. 12 hours per half of the world.
So you'll get to see, you know, a lot of different things, whether you're a developer, an executive business person, or a DevOps person. Gen AI for DevOps is one of the topics. And then it will repeat another 12 hours for the other kind of like how the eclipse goes around.
Uh, that's fine. All right. And you can get to the Tech strong events, but Mark, what is the URL for the event, isn't it?
It Is the AI enterprise Online. So yep. The AI enterprise online, The THE, the AI enterprise online.
You could go right there, you know, registration's free. We'd love to have you on there. We really want to make this the biggest AI event out there.
So sign up. We, Mark's done a great job. If you, you don't follow his artificially Intelligent Enterprise newsletter and stuff, you're missing out on a lot of great AI news.
I know. And you know how right up for that. For sure.
Yep. Alright. And happy Thursday everyone.
Enjoy the rest of Text Strong tv. We're not live on Friday as usual. Have a best of, but we'll be back at it on Monday.
Thank you. Cloud native now is the web's leading resource for the growing cloud native ecosystem. com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes serverless, cloud native application development, microservices, service mesh, cloud native security, and more.
Stay on the cutting edge of modern application development at Cloud Native Now. Hey everyone, hope you enjoyed the Textron gang today. We had a great discussion with our, my friend Mark Kinkle and Mitchell and, and Bonnie Schneider.
But now it's time for the rest of our Tech Trunk TV show today. Um, first up is one of my favorite interviews. I do it every year right before RSA.
And this is with Cecilia, RNA Cecilia, uh, is heads up the innovation and, uh, and scholars at RSA conference that includes the sandbox and startup stuff. And she came on to tell us what to expect today regarding that. And RSA this year, which starts May 6th.
Cecilia's a great person. She lays it all out. This is a great interview.
Check it out. This is techron tv. Hi everyone.
We're back here on Techstrong tv. You know, it's getting near that time of year and I am not talking about Christmas. I'm talking about RSSA conference.
It's about a month away. We are pumped here at Textron. We've got so many things going on for RSA.
We've got our DevOps Connect DevSecOps seminar. Again, I've got, got an amazing lineup of AI speakers headlined by the very famous sci-fi author David Bri, who's multiple Hugo Nebula Awards, PhD from nasa, jet Propulsion, JPL movies, books, everything. And we kind of great speakers.
In addition to that, we're gonna be live at Tech at, uh, broadcast Alley all week. Uh, we're putting, I have a panel I'm doing on what's next in DevSecOps. This woman right here is the lady behind the Sandbox Innovation Sandbox.
And everything else that's been grown was originally just a sandbox. Now they've got all kinds of programs around this. Um, I've had the pleasure of interviewing her for years, literally on our show.
And to me, RS a's real when Cecilia's on, let me introduce you to Cecilia Mar. Perfect. I hope I do it right.
Perfect. You did great. You know, after a certain amount of years, it kind of sets in Cecilia, it Rolls off your tongue.
It rolls off your Tongue. Well, I'm just back from Paris too, so I, I had a little practice. Um, anyway, Cecilia, it's so great to have you on.
You look fantastic. How's everything? Things are great.
It's such an exciting year. I know this is crazy, but, and I say this every year, so I feel kind of like I gotta, you know, shake it up a little bit. But honestly, this is gonna be the goat.
We have so many great, amazing things coming this year, including you, Alan, you're gonna be there. We're excited. We have a crazy great lineup for our keynotes.
And we just announced the top 10 for Innovation Sandbox Contest. It's gonna be fun. I can't wait Either.
Can I? I, you know, I just, I can't wait. Um, Cecilia, yeah, we, we've got people out here.
Some of our audience, a lot of our audience are cyber folks and they'll be at RSA. A lot of 'em are DevOps. They may be at RSA too Cloud Native Digital Transformation, of course, AI folks, but not everyone is probably familiar with the Innovation Sandbox program that you've been running over at the RSA conference for, what is it now?
It's gotta be 10 years more, 15 years, 18 years. Alan, Alan, you're making me old Man. No, you weren't doing it all the time.
I know. I was saying that actually the contest itself is 19 years old and, um, and it had had just an incredible run of picking really important companies that are shifting and changing our industry. So it's so amazing to be working on this program.
I like it a lot. So, you know, RSA conference is committed to supporting and amplifying innovation. We try really hard to help our community members hear from companies that are developing novel approaches to attack the complex problems facing our industry.
And the Innovation Sandbox is the, the leading platform where we just announced the top 10, as I just spoke about, uh, in, they will be on the stage on May 6th. And so a super fun group of people, you know, this co this competition has actually had the luck, or not necessarily luck, just amazing track record of all of the companies that have come on here. There's been 80 acquisitions over 13 and a half billion in investments.
We've had Phantom Win Big ID exons recently, TALEN Security, and last year was Hidden Layer. So those are names, you know, they, they came to our stage in the beginning of their launch of their really big, uh, uh, announcement to their, to the whole audience. And then it really has shown us how important this contest is in launching these these companies careers.
Absolutely. You know, and it is, it's, it's, it's, it's become the showcase for up and coming security companies and and what a feather in the cap it is. Even not even a win, even to make the top 10 finalists top Tech, I mean, yeah.
Yeah. 13 and a half billion in investments. Those guys have done very well.
Extremely well. Absolutely. It's, it's crazy.
So let me ask you, how do you wanna do this? Should we, do you wanna run through the whole top 10 or do we say, if you want to see it go to the RSA site? The RSA conference site?
How so? Yeah, your call, I kind of wanna do two things. One, I wanna talk a little bit about the trends.
So yes, you know, when you're thinking about what is the most impactful technology that's just happened in the last 24 months, it's artificial intelligence. And so in the top 10, you're gonna see many of the companies either talk about, you know, large language models or the gonna be using Gen AI in order to really, uh, increase the security team's productivity. You have companies that are creating solutions to help you find these fake deep fakes, uh, the applications to ensure that you're, you're going against the adversaries that are using these technologies as well.
I think some of the other pieces that are really important is just the judges that are here, not only are veterans onto the ISB panel, but they're also representative of leaders in the industry from different voices and different perspectives. So when they were choosing these companies, you know, you had a venture capitalist with a Sheem Chandra from Greylock Mm-Hmm. You had large security company strategists with Dory do from Checkpoint, uh, who's the chief technology officer over there.
You have Nilu Howe, who is, um, who is on the pulse of national security. You have a successful entrepreneur, Paul Kocher, who has demonstrated how to take a company out from, uh, from the nascent stages all the way to exit. And then you also have, uh, Nazarene Reza, who is the CISO at Verizon.
So all those perspectives came together and they helped choose the top 10. And I'm not gonna highlight any specific company and it gets too long if we actually talk through the names, but go check 'em out. It's gonna be a really incredible lineup.
I love the companies that are gonna be there. Where can we go check out Out? So you go to, um, you go to the RSA conference website, you go to the events page, and you get the innovation.
And not only can you find Innovation Sandbox with the top 10, you'll see their logos. Uh, you can also check out a little bit more detail if you read the press release. 'cause we did put a small snippet of each of the company's names, but off of our website, you can actually click through to find those companies.
Um, but when you're there, you can also be checking out all of the other innovation offerings, because this year we have some really cool things coming with Launchpad. I'm just gonna briefly touch on that because I am really excited about the judges there. It's Enrique Salem from BA Capital.
Sure. You have Sarah Gao from Conviction. She started her own firm, but she's a Greylock Venture, uh, veteran.
And then you have also Bar Mfta who used to run, uh, alien Vault and now has started Ballistic Ventures. So, I mean, again, like just Stellar. And before Alien Vault, he had another good company before Alien.
So I would, full disclosure, I was on the board of advisors of Alien Vault. Okay. And, but, um, good job, Alan.
Yeah, no, they did great. Sell good. But the company they did before was pretty good too.
Oh. Um, they had a good exit anyway. Yeah.
I mean, these are, these are giants in the community. Yes. Cecilia, for people who, again, who may not be familiar, the difference between Sandbox and Launchpad.
Okay. You know what, I'm gonna do three there because Alan, I have to tell you, we did something about naming that has been, uh, little bit of a challenge for us about Sandbox. So the Innovation Sandbox Contest is our 19-year-old contest.
It's taking companies that are in their, they're ready to go to market. They have the product that is going, that is, has been launched, and they have the team in place in order to actually make an impact in the cybersecurity market over the next 12 months. Launchpad is aimed at an earlier stage company.
It's a company that probably doesn't have their product out, or if they do, it was, it's coming out right before or at conference. And the goal here was kind of building out something where we could demonstrate where trends were happening earlier on. With Launchpad, it's a shorter contest.
There's only three companies that are gonna be there. And basically it's a little bit more like Shark Tank, where at the end of the, at the end of the pitch, he will ask the different, uh, VCs, are you in? Would you wanna see this company again?
And I have seen those companies and it's really cool to see some of the solutions that they're coming out with. So I don't know who's gonna be picked, because that's happening on Friday. You have to wait till next week.
Mm-Hmm. But, uh, that's gonna be, that's what launchpad is. And ISB has just, um, has just announced their top 10, so they're ready to go.
You can check those guys out. Great. And the Last one I forgot.
So Sam, Oh yeah, the third one. The last, Because these are your friends, Alan. This is, um, where we have created this like kind of hands-on zone.
It's, it's in the actual location close to Innovation Sandbox, but it's in the zone where what we've asked is to have different, like basically def com villages come in and do some hands-on activities. And so you have the ICS village and the IOT village and the AI village, and they all give you like a little mini sampling. And it also has talks on a stage that are, are more aligned with some of the, you know, cutting edge research.
And then you have, oh, and Cloud Security Village, there's eight villages. Oh. And including, uh, the Idaho National Labs and cisa are bringing an escape room.
So you wanna come play in an escape room. I know. That's, it's super, super fun's.
It's super fun. So I, I'm excited for this year's, uh, innovation area. It really is gonna be packed and fun and come, come play with us.
Absolutely. You know, last year at RSAI, um, I felt like wow, COVID is in the rear view mirror. I think we were back up to like 40 something thousand people.
Uh, it felt like RSA again, this year though, I'm expecting a record breaking. RSA How are, can you comment on that? How Are our numbers?
Our numbers are good. Our numbers are good. I heard, I will, I'm not a betting person because I don't like to do that.
But what I can tell you is we are trending very well against our own expectations. And so I feel good about, um, do I about the numbers that you Suggest to I'm so looking forward to what I'll Say. I, I hear, you know, we'll be there all week, as I said on broadcast all, uh, and I'm look r rs a's a highlight for my, has been for many years.
Um, Ceci, you know what I realize not everyone out here, we tell 'em go to the RSA conference website. com or RSA Conference us now. I forget.
com and then if, if you go up, you can see the events and in there it, in one of the tags, we'll Have r USA conference slash USA Do you know, events? But Now that we've, now that we're back, Yes. Can we start doing RSA again in, in other places, Singapore, Abu Dhabi, we've done in the past London.
What are, what are our plan? And I realize you're not the be all in end all for all things RSA conference, but, But what do I know what You think? What do I know?
What do you know? What do you know what, just between us, I'll give you the inside scoop. You know, we do have a vision to really start spreading our wings again.
Uh, it's gonna take, you know, a year or two to kind of get ourselves back to where we, back to finding the locations and, and being strategic about it. Like finding how to really increase you the community's value out for this. Our goal is not to do conferences.
Our goal is to build a community, and we can do that, and we need to get to those locations in order to do that. So our objectives in the next 12 months is to really kind of fig flesh out where we should be going. And that's where I'll leave it because it's, uh, all, Well, look, We've discovered, Hey, you've got a lot of ideas here, though.
We're open to getting, uh, feedback. Oh, I have ideas. We'll give them to you.
But, you know, it's a dangling metaphor. As I said, there's nothing matter with Amsterdam, Paris, London, Prague, any, any of the cities in Spain are nice. Yes.
Um, but we'll talk, we'll talk more, um, Cecilia, all kidding aside, we gotta wrap up. But first of all, congratulations on what you're doing with the sandbox and, and launchpad. Thank you and everything.
Thank you. It it, it serves a very important purpose because innovation in cyber doesn't necessarily, doesn't usually come from the companies up here who maybe are supplying judges. Innovation in cyber starts at the grassroots level with startups and with new companies, with new ways of looking at things and new ideas.
And so it's, it's so important to give these companies a glide path to take off. And this is the best one there is. Yeah.
Thank you. I, I mean, we've done a lot of effort on this and we're still building it out. We really do want to amplify innovation as we, uh, it's one of our missions.
And I really believe that the creativity from the good guys is absolutely essential to go against the bad guys. 'cause they are creative. Yeah.
But the startup, They are creative and well-funded. Yeah. Absolutely.
Yeah. And then our startups are nimble and the people have great mission, great vision, and they, it, it's just been really fun to spend 10 years in this and see just how far we've come and what we're doing next. And I, I, I really am proud of the cybersecurity community.
It's always amazing to me how they step up and they, they pivot quickly. They adapt new technologies, they build new solutions. And if our whole idea is to help that community and to pro provide them this platform, then I hope we're doing the right thing and we're doing a good job.
And, and, uh, again, we'll take feedback. Absolutely. Great, Cecilia, best of luck.
Can't wait to find out more and see, and maybe we'll be interviewing some of these finalists as well before. I hope you do say, I Hope you do. Uh, I'll be gonna talk to someone I know who can help me there.
Um, Cecilia Mario, yay. Senior Director Innovation and scholars of RSA conference talking about the innovation early stage startups at RSA conference coming up in about a month. It all starts on May 6th, Monday.
May 6th through Thursday. I, I guess that's the ninth, Cecilia. Great seeing you.
Great seeing you, Alan. I'm looking forward to seeing you in person. Me too.
We're gonna take a break here on Techstrong. We'll be back in a minute. Next up, I've got my friend Mav Turner, who's the Chief Product and Strategy Officer for tricentis.
Mav is gonna discuss Tricentis latest state of mobile application quality report with some interesting findings there. Here's Mav Turner. This is Textron tv.
Hi everyone. Welcome back here to Textron tv. My next guest is my friend Mav Turner.
If you've been watching Techstrong tv, you've seen Mav on here a few times. Mav is the Chief Product and Strategy Officer at tricentis. Good partner of ours here at Techstrong, as well as just the wealth.
They're the worldwide leader in continuous testing. Right. Um, hey, Mav, welcome back to Tech Drunk tv.
It's great to see you. I hope all's well, Everything's great. Thanks for having me, Alan.
Uh, always fun to talk with you and your audience here about, uh, what's going on in the world of quality engineering. And, uh, again, for those of you who may not know Tricentis, uh, as, as Alan, uh, graciously introduced us, uh, the worldwide leader in continuous automation, uh, in addition to automation, a lot of folks are, are using us for test management, performance engineering. Uh, we have quite a broad portfolio.
But if you're thinking about how do I deliver quality with software, uh, Tricentis probably has something for, for you there. Absolutely. com, of course is the website.
Um, and you can go check it out and, and that, that's a, you know, ma I noticed, I I'm outta date, you call it worldwide continuous automation, not just testing, Right? Yeah. We, we, we've really expanded beyond just the kind of functional testing concept, right?
If you go back to our founding, that's what most people know us of, right? I'm doing testing, I'm trying to move from manual testing to continuous testing, that we've been really big in that for a long time. And we think about the quality engineering process, and we think about what needs to happen to deliver high quality software.
That's where we get into how do I think about test management? How do I think about performance engineering? And to segue into some of our conversation here, you know, as mobile becomes more and more important, how do we make sure we have coverage of all the technologies in the enterprise and in your application environment to ensure success?
And so that's the continuous evolution for tricentis here. Excellent. Glad I caught that.
All right. Mav, recently, Tricentis came out with their state of mobile application quality report for 2024. First of all, it, that's a mouthful.
What exactly is the report on? Yeah, so when we think about what we need to do to help our customers, obviously we're talking with them all the time, or we're talking with non-customers, right? We're trying to understand where there are the challenges and how can we best apply our resources, our technology, uh, to help.
Right? And, uh, so in addition to all of our one-on-one conversations with customers, we like to do industry surveys to help inform that strategy. And so to your your point about the long title here, um, we just wanted to understand from a mobile perspective, um, where everybody was, where do we think, uh, mobile quality is?
What do we think the gaps are? Where do we need to focus? Um, and, and get that kind of different perspective of, of research.
So, uh, yeah, we fielded this report, um, globally to understand. 'cause sometimes you'll get interesting data from different parts of the world. Um, but just to understand, yeah, what's the state of mobile application development and mobile quality?
Okay. And is this report based upon like survey data or interviews in depth interviews customer data somehow, or, you know, some other proprietary All of the above. Exactly.
Global survey, primarily survey. Um, so the mm-hmm. The survey's informed by the deep 1 0 1 conversations we have with our customers all the time.
And so that allows us to kind of frame out the questions we want to go deeper and more, more broadly. Um, so usually when you think about research methodologies, you think about, you know, how can a one-on-one qual qualitative conversation, uh, inform and drive a more broad scale quantitative analysis of the market, which then actually feeds back into our, our, our, you know, uh, future, uh, qualitative research with, with customers. And so it's a continuous loop.
It never, it never really ends, uh, which, if you're doing it right, uh, but yeah, this was a, a, uh, global market survey that, that we sent out a bunch of questions on to understand, you know, a couple of areas, again, where everybody is today. Um, you know, from a, you know, what are they doing? What do they think the impact of, of quality is in the mobile experience specifically?
Um, we think about, um, how AI is impacting, uh, their development processes and where are they using it. Uh, what their, do they think it's good or bad? Um, why, why is it important?
Right? Is is it really important? Should it be a priority or not?
What, what, what do the, the, the people think when we are, we're doing these mar market surveys, and then what's the future? Where are we going with, with, with quality? How do people think about their strategies and their roadmaps and, and how it impacts their, their business growth?
Excellent. Very cool. You know, do you have a sense in, in terms of the survey size of the audience that responded here?
Yeah, it was over a thousand people. Uh, like I said, global survey. So we have hundreds of people from the us, from Germany, um, um, and, and Asia Pacific and Singapore.
Um, lots of markets that we wanted to make sure to hit. Um, you know, the, the interesting thing I'll say from, from the size of the, the thousands of developers and IT professionals that responded was, um, the, that most, everybody's kind of struggling with a lot of the same things. And, and, uh, you know, there, there wasn't one pocket where, you know, um, yeah, any one country kind of stood out.
Um, one area I will, I will kind of peel back on that global topic is around the, um, sentiment around ai. And I'll tell you, I was somewhat surprised by this, and I think it's a, this may end up being a whole top track on this one topic, but, um, when we look at AI in the sentiment, and we split that out by country, um, the most positive sentiment was out of Germany about the impact, a positive impact of ai, um, in the context of mobile quality. And the reason I'm surprised by that, I'm curious, Alan, if you have any reactions to that yourself, was, um, generally we see more skepticism from that market, right?
More, more concerns, uh, particularly around data privacy and, and the risk of ai. But, but when I, when I've talked with a lot of our customers in that market, um, while they still want to apply this rigor to the adoption of ai, they believe and want to be leaders in the market when it comes to leveraging AI and see this as a huge opportunity, and not just in, in Germany and, and, and other European countries as well. Um, so they don't wanna feel like they get left behind here, right?
So they're very, very, uh, forward adopting here. Um, actually the US was, um, had had the least positive, I don't wanna say it was negative, but about 81% of people in Germany had a positive sentiment on the impact of, of AI and quality. Whereas in the US it's only 69%.
So there was a pretty big distinction there. Um, right behind Germany was Singapore, um, and then the UK and the US were kind of notably, uh, further behind. So I don't know your your, your reaction to, to some of those, those points, but I thought it was interesting.
Um, I'm, let me say, I'm not surprised on, on that last one, right? I, I, you know, it was interesting. I recently came, I was out in Paris for CubeCon, and then from there we went over to Sicily and Rome and some other places, and I, I'd travel to Europe a bunch, and I'd go to Singapore.
You should. Yeah. Yeah.
Someone's gotta do it. Uh, yeah. We appreciate you doing it.
Yeah. And then, yeah, I've been, I usually go to Singapore like once a year as well, and in that area of the world Pac, yeah, Asia Pac, you know, I, I think it reflects their usage. I think it reflects their values.
I think it reflects their goals. Um, that being said, for whatever reason, you'll see crazy innovation in the US and, and the UK kind of does mirror the US a lot more than it mirrors, let's say Germany. Right?
Agreed. Um, so I, I'm not saying that we're laggards or that we care less or we're, you know, but are we less optimistic or do we not even think about that? Just full speed ahead and dam the torpedoes That's actually ready.
Yeah, there is some of that too, right? Yes. Yeah, yeah, yeah.
You know, we'll, we'll, we'll think about it later. So what if we dive in the pool and find out at bottom, there's no water in there, right? It's all good.
Yeah, we would first one to dive in. Um, it, it's funny. Hey, you know, I do wanna mention though, before we jump more into the report, anybody who wants to go grab the report themselves, it it, I will put this, we'll try to put this in the, uh, notes on the, uh, video as well.
com/resources/mobile-application-quality-report. And you could get it from there. As I said, we'll do, we will try to put that in, in the notes for today's interview.
So, Mav, what was some of the other, like, big takeaways here? Yeah, kind of moving out of the, the AI question. 'cause again, that's, that's, you know, usually a, uh, you know, uh, evergreen topic.
Everybody wants to know about that. But there's a lot of other good, good nuggets, uh, we found out here as well. Um, we, another interesting thing that I got out of this report that, you know, you get a lot of anecdotal stories from customers, uh, but to do a survey at scale and you get responses that, um, when we talk about revenue impact and business impact of low quality, 'cause this is something that I think a lot of, we go down to the development teams and the application teams, they usually get a little bit too far from.
And if, and if they can kind of figure out how to tell that, that story about how their work impacts the bottom line, it really makes a more impactful story for what they're doing and why they're doing it and how many resources they need. Well, we saw that, uh, over 90% of the respondents set estimated that this poor quality experience cost their business up to two and a half million dollars in revenue. And so being able to quantify why it matters, why taking the time, um, why having the proper environment, the tooling, the people, the training to be successful can actually matter to the business.
And so I was, I was interested to see that very, you know, kind of clustering of responses around, around that number. So obviously some people said higher, some people said lower, but, uh, but it was a pretty strong signal there about real business impact being felt, uh, around poor quality. Yeah, absolutely.
Absolutely. What else? Um, and, and I think that's really, you know, paired well with the fact that, you know, only a quarter basically said that their current strategy exceeded their expectations.
So you say, you know, we know we're not doing well, we know it's having an impact. Okay, so now what do we do next? Right?
And so hopefully some of the things we talked about here, and if you go get the report that you just mentioned, people can start to figure out how can I make sure that this is elevated to the right priority level of business? Because the benefits are great, right? Um, if, if, if, if mobile is a key part of your business, um, then ensuring high quality by understanding the processes that you need to deliver that quality, having the right tooling, um, having the right just quality mindset overall.
Um, if they can move to more automated solutions versus, look, we, we all do what we can. We, I talk to some customers that say, our testing process is we deploy it to our internal employees, and they use it before we deploy it out to the field. And, you know, that's some, some companies that's what they do.
But as you move from that manual testing, ad hoc testing to a more automated testing that allows that human resource resource to really spend time doing things that, that only humans can really do with the exploratory testing. And, and that, that kind of same theme that Tricentis has been repeating, and again and again around, um, automation is, is still very critical. And we find that mobile applications are much less mature.
Um, and mobile application development teams much less mature in an automation perspective than, um, web or, or desktop based, um, application development teams. Absolutely. Very cool stuff.
Um, let's talk about mobile applications versus, I know you wanna call 'em non-mobile applications or traditional, you know, there was a time map, uh, I'm gonna say seven, eight years ago, where, I mean, clearly there was this fork in the road between mobile application development versus application development. A lot of, there were a lot of companies that focused solely on mobile app development, mobile app security, mobile app, this mobile app that it's my, and this is more of a gut feeling. I don't have kind of subjective numbers or objective numbers to to, to show to you.
Um, but it, there seems to be more of a, a coming together, right? That mobile is not just a totally different animal than it was years ago. I wonder if that somehow is reflected in here or maybe just from your own, you know, experience.
What do you think? A couple of things there, right? If you, if you go back to, and I'll use iPhone, obviously Android has its own similar story, but slightly different.
Um, you know, the original launch of the iPhone and, you know, weren't gonna have third parties being able to build custom apps. Everything was just gonna be developed by Apple. And then opening up of that app ecosystem, and I think around the same timeframe that you're talking about where you see this explosion of application developments, everybody's getting into it.
Um, they're building native apps and, and then, and then Android, I mean, has a massive market, right? Much larger than, than than Apple. And then you see, okay, now I have to figure out what, where my customers are, what devices and what, what, what I've seen is in the last couple years that we've really invested more in mobile, um, is really the, you know, react native, na native, these hybrid applications that have web and some native components.
Teams trying to, um, kind of build once, deploy twice, right? Instead of having to have, here's our, you know, iOS development team and here's our Android development team, how can we, you know, use frameworks like Flutter to build an application, um, effectively and reach these audiences? And, and not to get too much into the weeds, but it really comes into an overall well architected solution.
When you think about the backend, you think about the customer's experience, if you can abstract the business logic from the presentation layer, effectively, you can go really fast into building front ends, um, and the web, web UI or, or even a desktop app, maybe you have a, you know, a desktop app you wanna run, um, and a mobile app. But if they're all hitting the same backend resources efficiently, um, then you really maximize your market capture. And, and I think through a lot of these frameworks and a lot of the, it's much easier to be an application mobile application developer today than it was 10 years ago, for sure, seven years ago.
Um, but there's still a lot of challenges. And, and I think what we're, what I'm seeing anyways is, um, with, with some of the advances in maturing on the development side, you naturally see more maturity on the testing and quality side that comes around that as well, right? But, but usually that is a little bit of a laggard compared to the development tool stack, which is iterating very quickly, um, the frameworks everybody's using.
And so when I think about it, I think, or when I see what, what's happening with our customers, um, I expected a lot of more just native development teams when we, a couple years ago when we kinda really started to go deep. And what we've ne mostly seen is the use of these frameworks, um, to actually build, um, build once and then kind of take advantage of these hybrid apps, which is much more prevalent than I than I first suspected a couple years ago. Absolutely.
Mav, we're about outta time, actually, we're over time. I apologize. We got kinda waylaid there, but, um, look, it was interesting stuff again, that this is the tricentis state of mobile application quality report for 2024.
com/resources/mobile-application-quality-report. Matt, thank you so much. Hope to see you back here soon on Text Drunk tv.
Say hello to all our friends at t Tricentis. Will do. Thanks for having me, Alan.
Alrighty. This is a shiel. We're gonna be back here on Text Drunk TV with even more news and information in just a second.
Standby. I am Bonnie Schneider, sustainability contributor to the Techstrong Group. I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter.
The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong Research Next up is one of my favorite, uh, video shows that we do here on Text Drunk tv, it's CD Pipeline. We do that in conjunction with the good folks of the CDF, the CD Foundation.
And in this one, well, this is a contentious one. We had a couple of folks around platform engineering, it's challenges, it's efficacy, how does it work or interact with DevOps, how open source ecosystems are driving it. Great, great conversation.
You don't want to miss this one. Check it out. Hey everyone, welcome to CD Pipeline.
Uh, if you haven't watched this show before, I should tell you my name is Alan Shimmel. I'm the CEO of Techstrong group and cd. The CD pipeline is a joint, uh, adventure, venture, adventure, whatever you want to call it, between, uh, Textron Group and our good friends at the CD Foundation, which of course is part of the larger Linux Foundation.
And, and if you're not familiar with the CDF, you really should be, they're kind of the leading organization that is advancing the whole CICD, uh, movement. And they actually are responsible for managing many of the leading open source projects within the CICD world, including kind of household names for those of us in here, such as, um, Jenkins, Spinnaker, uh, and more. There's about, I think, eight or nine different projects within CD Foundation, and we'll go over them.
But if we spend too much time on that, we're not gonna have enough time to talk about what I really want talk about to. And that is the subject for this, uh, for this episode of CD Pipelines. And it's decoding platform engineering, a critical dialogue with DevOps and CD leaders.
That aside, we're gonna dig into platform engineering and what do we really think about and how would it relate to ci, cd and DevOps and Agile and everything else? Let me introduce you to what I think is a monster panel we're gonna have on here. Uh, first of all, I want to introduce you to DSI ika, and hopefully I got that as best I've done so far.
dsi, welcome back to our show, man. It's great to see you. Why don't you introduce yourself.
Uh, thank you so much for having me again, Alan. I love being here. Uh, my name is, as you said, is DSI Ika, and I am the current board chair of the CD Foundation, as well as a member of the spinnaker Technical Oversight Committee.
Um, I'm just excited to be here and, uh, you know, waiting to see what the panel has to say. Thank you. Hey, the dc not to put you on the spot, but I got three projects in and, and my brain.
Yeah. Um, do you wanna do the rest to tell, just to remind our audience the rest of the projects in CDF? Sure.
Um, so you mentioned Jenkins and Spinnaker. We also have Ton orus, uh, shipwright, and of course CD events. Um, all of the projects, like you said, are are centered around, uh, CICD, and we are trying not only to advance the, the, the community of cd, but also think about what's the next set of tools and beyond, and how will CICD impact platform and how should platform actually recognize and contribute to CICD.
Um, and all of that is around the software developer's lifecycle. So that is, that is our main focus. Excellent.
Missed a couple, my friends. I thought there were eight, but I look, he's the executive director. I wasn't gonna call him on it, but Gloria, go ahead.
What? Uh, but you know what? Wait till I come to you and you fill it in.
I Got you. All right. Next up, let me introduce you to, uh, Nina Kani ne Nima Kani.
Excuse me. Yes, yes, no problem. Thank you.
Ellen. Nima Nani, uh, I'm a principal architect with AWS, um, and it's been three and a half, almost four years that I've been working with, um, you know, enterprise scale, um, AWS customers on DevOps and platform engineering. Uh, we've been building a lot of solutions.
I've been, um, a TOC member for spinnaker in the past. I have, uh, contributed to Argo cd. Um, and recently we started an initiative called Cloud Native Operational Excellence that looks at building better DevOps platforms for enterprise scale users.
And happy to be here to talk to you about DevOps engineer Nima, i'd, I'd love, I'm first of all, thank you for being here, and I'd look forward to having your input on this. Um, next up, let me introduce you to Tiffany Ja Jaha. Guys, I have to apologize.
I have Invisalign today, and I'm still, they're two days old and I'm still learning to enunciate better. But Tiffany, if you could pronounce your name and introduce yourself. Sure.
Hi everyone. Thanks Alan. Invisalign is tough.
Uh, I've been there, done that as well. Uhhuh, my name is Tiffany Chacha. I'm so glad to be here with you all.
I am an engineering manager at Autodesk, and I lead the platform, um, Autodesk Platform services support. So we work with dozens of platform engineering teams internal to Autodesk to represent our developer community, which includes over 200 engineering teams, and we help provide that initial support for all of their software delivery needs. So, touching on many of the tech stack that, um, here, the folks at the CD foundation are, are really helping to nurture and, um, and help the community, uh, work with, with different tools and, and for the purposes of, uh, better software delivery.
So, super glad to be here with you all to discuss this in more detail. Tiffany, thank you very much. Yeah, I definitely think it's that, like the CHSH sounds that I'm gonna have problems with.
But next up, luckily his name's fairly easy for me to pronounce. Andrew Fong. Hey, Andrew.
Welcome. How are you? Hey, good.
How are you today, Alan? Good, Good. Um, so I am currently CEO co-founder of pvoa.
We are building intent-based delivery, so to as a force multiplier for platform engineering. Um, spent most of my career in infrastructure, uh, from a OL to YouTube to Dropbox. And you know, we really think we're building a next generation of platform tools.
Companies like Rept use us to manage a hundred percent of their infrastructure in production at this point. Excellent and welcome. Thanks, Andrew.
Okay. And then last but not least is my co-host, actually. And, and since our last taping, she has a new title and a new job to announce as well.
We'll give her a chance to say it right here, but she's all thanks to A lot of open source really helps in a lot of these foundations and a lot of capacities, my friend Lori LaRusso. Hey, Lori, welcome. Thank you, Alan.
And yeah, so I just, um, started with Perona. So it's all about open source. I'm the head of community and it's my second week, so stay tuned for lots of good things to come.
Uh, lots of interaction with our users and I'm really excited to help, um, to help kind of shape the future of, uh, of Perona and their community involvement. That being said, I am here because I represent the CDF and Alan, you get everybody every time when you ask us to list the projects. Did see he did it to me, puts you on the spot and you just forget some.
I mean, there's only eight, but when I say only eight, these are eight amazing projects. And so let me just give you the list. And I am cheating.
I do have my phone in front of me. Oh, okay. So No calculators.
Yeah, as Didi said, we have CD events, uh, Jenkins, uh, Jenkins, X Ortus, screwdriver, shipwright, Spinnaker, and Teton. So we kind of cover the entire smorgasbord of CICD, and I am absolutely thrilled to have this, uh, conversation today, um, to have the spinnaker team with us, to have Andrew and Tiffany to really kind of dig in to this whole idea of platform engineering. Excellent.
com, I initially had a pretty visceral reaction to the platform engineering movement because I, I felt like they were, and maybe it was just a marketing play, you know, saying that that whole DevOps is dead long lived platform engineering, and I, it was marketing, I think, or maybe not. We'll hear what you have to say. But over time, I've, I've softened and, and come to respect what platform engineering is trying to do, and I think it certainly does have its place in this continuum of how we build, so build and deliver software today.
Andrew, I'm going to start with you if you don't mind. And, you know, I, I'd like you to kind of succinctly tell our audience what do you think platform engineering is, or what should they think? What should they know platform engineering is, and how does it fit into the kind of, you know, into the, the, the bigger picture, if you will?
So, I, I tended to think of platforms as sort of three levels. One is sort of traditional, it, you know, where you have, you have the piece of software you install, like probably what we're all familiar with in the early nineties, early two thousands. Then we kind of moved to this DevOps world of CICD.
I think that's kind of a level two maturity of like platforms. It's like, let's get self-service. It's our i internal developer platform, IDP sort of discovery tools.
I think there's like a third level of platforms, which I think is, goes very, gets flows, flies under the radar right now, which tends to be more about how you do app full cycle application development. So how does your RPC framework work? How does your, how do you handle monitoring?
How do you build an entire end-to-end application? Um, which is a very different place. And I think most organizations right now are somewhere between maturity levels one and two in that mental model.
Um, I think it's a good discussion today to see like, okay, you know, CDF probably focuses more on the level two versus sort of the level three, um, uh, like altitude. But I'll pause there. Is that, I see how that resonates with people on the, on the panel Guys, what reactions to that?
Come on. Someone's gotta have an opinion. Yeah, I, I think that's a, a good way to look at it.
I, I will, I personally think that, um, the platform movement in itself is more of an obfuscation of the tool sets below it. Um, and being able to have a rich set of tools integrate into the platform concept will be always be driven by the DevOps folks, will always be driven by, uh, CD folks who are trying to give excellence with the tools. Underneath.
The challenge becomes how do you take, um, a lot of different types of tools, uh, you know, and then create specialized platforms that, that meet your service needs and your service goals. Um, I, I think that's one of the reasons that, uh, the, the canoe project is so interesting, uh, as they try and figure out, okay, you, you already have tools and things you'd like to use, how do we give you a platform on the fly with that that is, is useful and available? Um, so our focus of course, in the CDF is the tool excellence and, and having that ability to, uh, separate your software delivery, uh, lifecycle workflows, um, as well as making sure that the tools underneath your platform are excellent.
Fair. Anybody else? No.
So let me, let me jump in then. I've been known to have an opinion now and then, so Andrew did a good job of delineating different levels, if you will, uh, of, you know, of, of engineering, of platforms and, and how, how this plays out in my mind. There's a couple of things here that actually are good things.
Number one, I think one of the problems we've had in, in DevOps in general has been the move to just throw more stuff on the developer's back, right? DevSecOps? Yeah.
Let's make our developer's security people, they're not security people. They, they care about security testing. Well let the developers do more testing, right?
Uh, the developers are probably the highest paid people in the food chain right there. The idea of just throwing more stuff onto their plate until, you know, the, the, the proverbial straw that breaks the camel's back, it doesn't seem like a very efficient way of doing things. And that includes having the developers try to architect and maintain their platforms, right?
So the idea of having an yet another team and, and the idea of building another silo, I get it, is anti DevOps. But the idea of having a team that helps facilitate a, a working platform instead of tools that the developers can then do what they like to do, which is code makes perfect sense to me. I also think that a lot, and back to Andrew's, you know, kind of delineation of the different kinds of platform and platform engineering, I think a lot of the ops functions that we've historically had that maybe would give it short shrift and the whole DevOps movement are still very valid and necessary.
And platform engineering gives those ops functions, a a new home, a new fresh breath, a new name, if you will. And if that's all it does, it's still helping shine the light on these very necessary, uh, functions, these very necessary tools and processes and so forth. I think this is a good time for Tiffany to kind of jump in because this is in essence what she does, right?
Yep. Like manages the team of, so, Tiffany, what are your thoughts on what Alan just said? Yeah, I actually, I love how everybody mentioned sort of two underlying factors when it comes to platform engineering that I, I'd like to highlight for anyone who's listening, the first being that sort of scale slash customer facing or developer facing aspect to it, right?
A lot of, like, I, I think there was a lot of initial pushback on platform engineering as sort of this replacement to DevOps. But when you think about it, the reason why we've introduced platform engineering or platform solutions is to better address the needs and concerns of the developers that we're serving. And so, in effect, dev platform engineering is almost like the DevOps practices scaled in a way to meet enterprise or bigger organization needs.
And doesn't have to mean that you have a thousand person and, uh, organization or, you know, a thousand developers that you're, uh, serving, but it means that there is a sort of stakeholder management or community involved in the usage of the different solutions and automations that you have in place to deliver your software code. The second aspect that I think is worthwhile to highlight in platform engineering is the sort of evolution of like, the creation of a platform, which I think a lot of traditional DevOps didn't necessarily have their development or their work tracked in a roadmap and in sort of this, this sort of more traditional dev, uh, development oriented workflow. So one thing that we're starting to see is, you know, these platform engineering teams, the way that they're set up is they'll have a product manager, they'll have a roadmap, they'll have plans that sort of mix, uh, development work, platform development work with operations work, right?
And that further extends the collaboration with security teams, networking teams, infrastructure teams. So I, I do think that there's a lot of, um, now like a, a home for DevOps oriented work that traditionally didn't really have that much of a home in traditional DevOps. So I will say that there's a lot that kind of got introduced with platform engineering, but I, I think it's a wonderful idea to look back at, you know, what does platform mean to you?
And like, what does it mean to build a platform? Because at the essence of it, that's what platform engineering teams are doing. Can, can I, can I jump in?
Um, sure. On that? I, I think one thing, and I think, um, uc said this earlier, that, um, like c, like c ncf, F and CDF are focused on tools.
I think that the number one difference between platform engineering and the way, like the approach of DevOps, the approach of SRE and all the rest, right? Has been that it's workflow oriented as opposed to tools oriented. And I think if you start from the tools, you fail every single time, um, because you're look looking at a very specific slice of the, of the workflow, and you're not actually looking at the totality of what the, of what's trying to be accomplished.
So I gotta jump in. com, I have to say, anyone who tells you that DevOps is focused on tools doesn't know DevOps, right? If you speak to Patrick dubois or John Willis or Damon Edwards or any of the people who started the DevOps movement tools is always third, it's about culture, right?
It's about culture, it's about people. It's the tools. Tools are interchangeable today.
Today it's Jenkins. Tomorrow it's spinnaker the next day it's something else. But DevOps isn't about if you, if you are focusing the DevOps as tools, you got it wrong.
So I, I want to, what I say there is that what you said is a focus on culture. What I said is work workflow, and I think workflow is a product. Culture is not a product.
You cannot sell culture. Um, and so culture is an attribute of leadership, right? And leadership actually has to actually do that, right?
And so what you've pointed out is that leadership is failing at creating a culture. Um, but what they're, and what they're doing is empowering building Of DevOps isn't working. I, I assume you're assuming DevOps doesn't work, and it must be a failure of leadership and culture.
I, I, I disagree with that. Um, if that's the case, I think if you're gonna look Developer, Yeah, excuse me. Uh, I would say that if that's the case, right?
Then you'd look at things like the DX surveys and all the rest, the NPS scores of engineering organizations, right? They'd be significantly higher if it was working, right? So all like, let's, let's forget DevOps, forget everything else, right?
Let's just take from, uh, from a factual standpoint, let do engineering organizations feel today, right? And they feel disempowered. They feel like they can't get their work done, and they feel that, um, that the workflow is broken, right?
So now we can, we can say that there's like, doesn't really matter 'cause we can just go back to first principles. It doesn't really matter what, um, how we got there, right? We have a problem.
So from first principles, right? Like we can split it apart into three pieces, tools, technology or tools and technology, culture and, uh, workflows and, and the product of the said thing, right? And we can look at each of those independently, right?
And we can say, how, how, how are they, how are they doing? Right? Um, from we know that there is no workflow, right?
We can look at the, the, the engineering teams are basically saying there's no workflow, right? If you look at the surveys that like that come out today, then you look at the tools, they like the tools, they're just complicated and they'll fall in the middle on culture, right? And so, like, all three of those today have some deficiency or some major deficiency.
So I'm not saying DevOps is failing. I'm saying that like in totality, right? Like it's not actually producing on either side of it.
So, Andrew, let me ask you a question. You are looking at today's surveys. Let's go back before there was a DevOps.
Do you think it was Nirvana and everyone was happy? Do you think it was bad? I bad 12 years ago?
I'm not saying, oh, I, I don't know if it matters what 12 years ago looked like. It only matters what today is, right? Because it's like, the question is How might, well, you know, there's an old saying, when you get a little older, you'll learn this.
Those people who don't learn history are destined to repeat it. Oh, and what I'm telling, telling you, I've been in this game for 30 years, and when you go back 25 or 30 years ago, there weren't a lot of happy campers. There were a lot of burnt out people.
And the, and the, the, the banging between developers and operations and, and testers and security was pretty bad. Things have gotten better. The, were they perfect?
Are they perfect? Will platform engineering make them perfect? No, they're never gonna be perfect.
It's the nature of the beast. Oh, I think that's totally true. I think that the, the one thing that changed, right?
Because like, um, the one thing that's changed, right, is if you look at the current set of talent coming up through the industry, they've never seen anything but a cloud native world. And so that shifts the perspective of what they expect and how they expect the tool chains to work, right? And how they expect culture to be and how they expect, right?
And so if we, we can look back and say like, historically, yes, it was not great, but we also have to look at like, again, from first principles, like what does the current set of talent in the industry look like, right? What do they, what do they want? How, how have they expressed?
How are they expressing their needs? And if you, and then you project out five years, right? Like, what do they want is not the world.
Like, 'cause they've, they've seen enough of what's here today that they're saying, you know, I'm 25, I've never seen anything besides AWS and now I'm a tech lead. I'm getting, you know, my career path is the X. And they're saying like, look, I need a different set of tools.
I need a different way of operating. Um, I'm not saying platform engineering is nirvana. All I'm saying is that, uh, that the, that what is there today doesn't work for the current set of talent in the, in the industry and coming up through the industry.
And they're basically saying they're rejecting it. So I'm gonna jump to Nima 'cause I've seen you nodding your head on quite a few points. Um, speaking of companies, he listed yours, so why don't you kind of weigh in a little bit and give Andrew and, and Alan a chance to kind breathe for a second.
Yeah, definitely. Well, I mean, very interesting conversation so far. And I think, you know, when I look at DevOps and the evolution to platform engineering, I think for me at least, things have changed are that, you know, practices of deploying to production are actually increasingly becoming more complex.
And if you look at, um, you know, deployments, I think, you know, there are, or when you look at DevOps engineering or platform engineering, you have to look at the capabilities that you want to kind of deliver to your, um, to your end users. And I think it's becoming increasingly more complex to think about the capabilities that are available or the requirements that your developers have, right? There was a point in time where the only requirement for deploying to production was that you actually find a server, you drop your binaries there, and then you kind of open the HGTP portfolio, the world to access your application.
Things have changed quite a bit. Right? Now you have to deploy to cloud, you have to look at continuous delivery, you have to look at running tests, you have to think about security secret management to identity access, you know, load balancers, DNS servers.
So there's a lot more that you need to think about. And I think DevOps engineering was actually giving you practices and patterns that would solve it. But one of the things that I think we, we are seeing now is that there is a lot more tools now that can act, that can give you the requirements that you have that can actually provide you with the set of capabilities that you require.
So I kinda agree with what Tiffany said earlier, that, you know, platform engineering is created to solve for the scale, you know, how many engineers you want to support, how many applications you want to support, and how many users you want to support. But more importantly, how you can actually provide consistency for all your application developers to actually do the same thing over and over with less deviation across the board. And how you can actually make it simpler for your application developers to think about, you know, deploying their applications, how can you reduce the number of, um, you know, requirements that they need to address and provide consistency and reliability, right?
So if you start thinking about DevOps engineering in the context of capabilities that you want to provide, and then the tooling that you want to support to provide those capabilities, and then to kind of create the culture and create the set of practices so that as your application developers change teams and, you know, move from one side of organization to the, to another side of organization, they actually have to deal less with, um, you know, the new set of tooling, the new set of overhead. I think that's the purpose of platform engineering. So when we look at platform engineering, at least in the context of conversation that I have with AWS customers, it's about creating that consistency and it it's about reducing choice, um, and, you know, giving you the right wiring for the set of tooling that you have so that eventually you can bring, bring that scale and consistency to your application developers, right?
Um, I think it's important to think about consistency when we talk about platform engineering. The whole effort of engineering is to make sure that we have consistent, reliable and secure practices over and over available to application developers. I'll, I'll make you pause there, but I, I'd like to hear Whatever.
No, I, I agree with you. The only point I would take NEMA is I, so I personally was never a big believer in the term DevOps engineer. I don't, I didn't think that was a real job or a real function.
I do think a platform engineer is what that role should be, right? Making that platform. Totally.
I think we have CICD architects, engineers, if you will. Um, but I think at the end of the day when we talk about this, it's about how do we let the developers work faster, better, more quality, and more in concert with ops? And whether those ops or platform engineers or something, what, whatever you're gonna call 'em today or yesterday or tomorrow, it it that, that it has to be a better connection, a better fit where people's, you wanna call it workflow processes are more defined and, and so it allows 'em to go faster better.
Yeah. And that really is what we're, we're after here, I Think. I think one thing that we also need to be careful about is that, you know, um, if you look at the CNCF landscape, and this goes back to what Andrew also said initially, there used to be a point in time where you could deploy Jenkins or you could deploy a spinnaker for your application developers.
And they pretty much had everything they needed in order to deploy to production, right? Spinnaker did a particularly good job in, you know, creating that developer workflows and having like an all inclusive tool that you could give to your application developers and kind of define their practices. It, now, if you look at the CNCF landscape, there's like 370 different projects and each one of those projects only addresses a subset of the requirements or the capabilities that developers need in order to deploy to production, right?
So when we think about platform engineering, it's a matter of figuring out first of all, which one of those 370 you want to to choose and how you want to compose those tools with one another to eventually bring the practices closer to what they used to get with something like spinnaker, obviously there's more to it, right? But spinnaker did a lot of stuff at one point, and, you know, a lot of the customers that I talked to at AWS are the ones who, you know, wear on a spinnaker uses spinnaker for a long time, and now they're in the process of modernizing their platform, but they need to rebuild that spinnaker experience with these 370 different tools that are available to them. So the engineering aspect is deciding about choice, is deciding about composability, is deciding about the capabilities that they want expose, and the engineering aspect is them putting them together for, for the cohesive experience to become available to the application developers.
So since we've mentioned Spinnaker, um, and I talked about this before we went online, uh, Andrew had a really nice, uh, LinkedIn post the other day about Spinnaker. So when Nima talks about how, you know, it used to do one thing and now you have to really like rethink your processes. Andrew, what, like, what are your takes on this?
Because I know you've got some, some opinions. I think that Spinnaker was, so, I think Spinnaker is built for an era of individual machines. Um, and it's been adapted for cloud native workflows.
Um, you can see it in sort of how it's been built. I think it fails on a couple dimensions. One is manageability from, like, you need a team to manage it and set it up, but like, like every single thread, right?
If you go into spinner or Slack is just like, how, how do I set this up and how do I upgrade this? Right? Um, that's like one big part of it.
And I think the other part is what Nima touched on is that the composability of it is low. You have to be a developer to compose on top of it. Um, there's no way to squat new backends into it without actually being a, almost a full blown developer.
Um, and so that I think limits the ability for it to stay as a central orchestrator. Um, I think what it has done exceedingly well, and I think the most underrated, um, blog post probably in the last five years in delivery is the managed delivery blog post from Spinnaker. Um, that entire post is, in my opinion, like probably what the next three to five years of CD of CD should look like for teams.
But it's very, very, it flies under the radar. Um, but that post, it's like, I think the website is managed do delivery, literally managed do delivery outlines exactly the pattern, in my opinion, that people should be looking at. Um, it flies under the radar and it's not, it, it requires a lot of leadership buy-in to get started, I would say, because it is going to separate responsibilities in a way that people are not used to.
Um, but if you do it, it actually things flow way better from what we've heard. Um, just like talking to people that have adopted the managed delivery pattern. Um, but it is flies under the radar.
I don't think they did enough to publish it and like actually push on that. If I had to say one thing to c ncf F like, or CDF, like that workflow is substantially better than everything else Out there. That's like we should do.
com or Cloud native now. Then Andrew, if you wanted to take that up, I'm giving invitation. We'll put it on cloud Native dead Larry, Uh, so did DC as person on the Spinnaker TOC and the CDF uh, board chair, like, why, why are we missing, why are we missing this?
Why are, why is this the best kept secret? Um, you know, what, what's your take on that? Like how, how did we deviate from something that could be so big?
Or how do we then push this forward and really kind of shine a light like Andrew said, that we should be doing? I, you know, I've heard a lot of wonderful things today. Uh, let me just say that first, I think the contributions of everyone has has been really, really, this is a great topic.
We should extend this to more shows around this topic. 'cause there's so much to unpack here. Um, and I think that, that, that's one of the core challenges because even in the managed delivery scope, you're still saying, Hey, there's a group of people who have to understand how to code and, and use this tooling to accomplish a thing so that that doesn't shift.
And to Andrew's point about needing a team to run Spinnaker, I I completely understand that it's a, it's a very flexible tool. Um, and it's that flexibility that gets, you know, folks in trouble. Uh, and so, you know, we in the spirit community, uh, recognize this and are working to make the lower the bar to entry.
So that's one of the things that we're actively working on. But I, I, I will call out that the thing that we're, I'm not hearing about is the other people who are moving into the space of needing to use these tools like data scientists, um, who need to be serviced and don't have this depth of understanding on all of the pieces. It's just the same thing that's happening to the developers.
And so we are talking about all of the pieces, like we, we've mentioned that there's a software developer lifecycle workflow that we need to account for, and that those are gonna be different and different people have different needs in that space. Managed delivery gives you that flexibility to kind of move around in that space. But you still need someone to be the expert to kind of guide that proc to practice and then map out very, very clear templates that people can use and say, okay, this is the way you get this to production.
'cause most of the, the developers that we're actually talking about, they, they having them having the need for them to learn all of the different pieces of the platform and understand how they come together and understand the DNS and understand all of the configuration, that's a lot of challenge for a new developer coming out of college who's never seen these things. It's a lot of challenge for the guy who's been working on one thing for 25 years that's this. Like, he is focused in on it on a product or a feature, and then it's like, Hey, stop, learn all of this new stuff for something you're gonna use once or twice.
'cause once it's set up, it should just work. And that's one of the things I will point out about Spinnaker is that once you get it up and it's just going, it just works. And so, um, I I I will, I will point out that managed delivery actually, uh, discourages the use of templates and encourages Exactly.
That's point's. That's my point. It's just about requirements, right?
Right. It's just saying like, define requirements for it, not, not templates to, you're not supposed to have to go understand DNS to use managed delivery. You're supposed to be able to just deploy with your requirements of my application requires X, Y, and Z at the app level.
Um, right. But coming from the opposite direction, if you are a CEO and you're going, Hey, I want everything stable, I wanna be sure that people are following the best practices. You, you want something that, you know, isn't just like, Hey, giving your set of requirements, like everybody's gonna do this thing, is the mindset, at least in the conversations that I'm having in the community with leaders that like, no, how do I make sure that, you know, there's DevSecOps, there's all these other pieces that need to be checked off.
I need a way to ensure that people are going through all of the steps all the time. And, you know, you're, you're now mixing the, the managed delivery aspect, and this is how it's suggested to, versus how leaders want their businesses to run. And this is the crossroad why this conversation is so interesting.
Right? No, totally. I, I mean, I, dick is that, this is where I go back to sort of like what you look at.
Uh, I I tend to look at it as, okay, there's the leaders that you're selling to today, and then there is the people that have only ever grown up in Cloud Native. And if you come from a world of where you look at something like Kube, right? Like the, the, the irony right, is under the hood, who Kube is not implemented as a checklist, it's a convergence system, right?
And so like all of the tech, right, that's there, all of the tech that's there, that works the way people think it works, doesn't actually do the thing they think it does. Yeah. So guys, we're in the middle of a research thing here at, at Techstrong on a, a large project called DevOps, uh, DevOps Next, right?
And we're looking at kind of what's next in DevOps. 12, 13 years in. And it, it's based on surveys of people.
It's based on interviews and it, but it's also based on what people are reading on our sites, cloud native DevOps, security Boulevard. And here's an interesting thing, and then Andrew, it goes to what you were just talking about, about for today versus tomorrow and and beyond. We all think cloud native is dominant and cloud native is dominant on new applications.
Like if you have a greenfield, you are, you are building it in a cloud native environment. But that doesn't mean that there's not a, I don't want to curse a, a bunch of of work, a bunch of applications, a bunch of infrastructure out there on AWS in the others that are not cloud native, that we can't, you know, maybe over time they'll be converted, maybe not, right? There's, but there's a lot of stuff that's not cloud native.
Even something as like DevSecOps. 'cause I come from a security background, I think, of course everyone is, you know, looking at DevSecOps and moving security left and, and whatnot. But the fact of the matter is, a relatively small amount of enterprises have kind of really adopted DevSecOps.
You know, we tend to live in a bubble and, and people on this panel as well, where, you know, we're always looking at the latest and greatest we're the, the classic early adopters of, of new technology. But when you look at that mainstream, right? And the classic models of crossing the chasm, 35% of the mainstream is a little earlier, and then this 35% later adopters, and then 15 or 20% laggards or whatever it is.
I think it's important to remember there's still a crap load of people who use Jenkins, right? The last CDF survey, 40% I think was the number of people doing C-D-C-C-I-C-D used Jenkins. And, and I'm not disparaging Jenkins by the way, I'm just saying that those are the numbers.
So it's good to say what we want it to be and what it should be, but we also have to recognize what, what our listeners, what our watchers here are dealing with. A lot of them, you know, say, I wish I could do cloud native. A lot of 'em, I wish I could implement some of the stuff, you know, that we're, we're talking about here.
But a lot of them can't, unfortunately because they, they're stuck in legacy land that's not Lego land. But, um, so I think, you know, we need a pack. I'm sorry, Dan.
Yeah. So I think one of the things that I, I, I get this question a lot, you know, working with a lot of AWS customers, there's a lot of legacy applications that run, not necessarily on Kubernetes, but other parts of AWS there's a lot of applications on premise that, that customers use. Um, so one of the things that is important to, to kind of remember is that, you know, there is a separation between how you manage your applications and how you run your applications.
And I think a lot of the conversations that we have, at least recently with a lot of the customers is that, okay, if you wanna go towards modernizing your DevOps practices and your platform engineering, you can have the management piece be modernized and still you can create the ability for this modernized platform to manage your legacy application, right? It doesn't contradict that, you know, you have a stuff running on bare metal, right? It doesn't contradict that there are parts of your application that have Jenkins and, you know, kind of execute the workflows for them.
Um, it is important to recognize this part of the modern modernization work that you wanna put in place. There needs to be some piecemealing work that, um, you know, goes into play. And part of that piecemealing is going to involve, you know, revamping your platform and having your platform kind of, um, you know, uh, cater to the legacy application as well.
So I, I don't necessarily think that people need to think that they're stuck with their legacy application only because they're using legacy tooling. No, there is hope, there is a pathway to migrate to more modern stuff. It's going to take a little longer, it's going to be more, um, you know, there's gonna be more challenges and it's gonna require more effort.
But, you know, the path to migration is there. And I think that's an important message to get out and let people know. Absolutely.
Absolutely. Guys, this was a lively discussion, but we're coming up on time. Tiffany, I feel like we haven't heard enough from you though.
I'm sorry to pick on you, but what do you think ha having ing to all this? Any thoughts? Yeah, I'd love to touch back on the managed delivery component because I think Autodesk and that ecosystem kind of sits in between level one, level two and level three, given that there's just been so much history at Autodesk with, you know, initially having like executables things that you download on the desktop and then now like moving towards a more cloud ecosystem.
And a lot of that has changed, and we see so many different kinds of workloads, like in my day to day, see so many different kinds of workloads. And one thing I've realized is that while you can have those ideas of modernization and like, oh, you know, this would be the ideal. A lot of times you have to be okay with sitting in the middle of all of that because it's work in progress.
Like, we have a ton of things that are configured as code, right? They're not necessarily templates, they're not necessarily self-service. And the way that you get your, uh, your code into production is, your applications into production is through configuration as code.
And it's a lot of configuration and it's custom configuration. And that's not even including the fact that you might have a complex workload, right? And that's something that is really helpful for people to like note, especially as they're developing platform and engineering.
The solution is like, how are you gonna bring the rest of your community with you? Um, and that's something that, um, a lot of people forget as well. Like, you know, we get so busy, we have the frameworks for the platform engineering, then we forget the culture piece of it, right?
So how do you throw in the culture piece of it back in and ensure that developers have a good sense of like, where this is going and is it sustainable and, and all the things related to that. So I, I just wanna sort of leave the, the open-ended question of, of that because I, I think a lot of support work developer relations type work is not really mentioned a lot in the conversation around DevOps, but it is very integral. Like, who, who do you have in your organization that's going to nurture the community and ensure that, you know, everybody's included when, when it comes to automating different workflows.
So just something I'd like to, to leave everybody with here. Thank you. Thanks, Tiffany.
Andrew, your closing thoughts? Um, my closing thoughts are, I think it is an exciting time to be working in the space of platforms right now. Um, I think that there's, that the amount of change just in the last 18 months is so high that it's like, it's really nice to see people actually caring about the space and realizing that it can be a force multiplier for organizations as opposed to cost centers, which is great to see.
Also, Andrew, we didn't catch your company's name, if you wouldn't mind. Wanna go check in? Uh, proa.
Proa. Perfect. I just wanna make sure people can get there.
Nema, I don't think you have to spell out AWS but your closing thoughts. Um, yeah, I agree with, um, with, um, what everyone else said. I think this is super exciting times for platform engineering.
I think there is, um, there is a lot of, um, new, um, technology that is coming out on a daily basis. There is a lot of interesting new challenges that you see. Um, you know, companies like credit, uh, Upbound, um, you know, you name it Acuity, they're solving at different levels of the platform stack.
And I think, you know, as these new solutions come out, it becomes, uh, more and more interesting for people to wanna compose this together and build that platform. So I think we're gonna be constantly on the lookout moving forward and deciding about what are the tools that solving, improving that, that productivity by smaller percentage. And, but those smaller per percentages at a scale, they come at huge value.
So, um, engineers are gonna be on, on the scouting, um, phase. They're gonna be looking out for these new technologies and pick up things so that they can improve the productivity of their application developers. Certainly exciting times.
Excellent. Thank you. The DC You wanna give us some closing thoughts?
Yes. I, I just wanna say that, you know, a lot of this conversation centers around cloud and I, I, it brings me back to my original conversations as I was beginning to join the CDF with Ericsson. And some of the things that they needed to deploy too just aren't cloud, right?
And you, you have this whole space of other things that need to be accounted for and these platforms as we move forward. And I think that's what the CDF is thinking of, like everything else from the tools perspective and how we connect this to make better platforms. Um, I'm, I'm gonna give a, a, a plug for something that Nima is working on, which is the Canoe project.
I, I encourage folks to check that out, just the thought process behind that. io. And, um, it, it is, it is building platforms from tools that you, that you already have.
And I think that's a, a great way to approach it and extend it beyond just this conversation of cloud. But how do we get that to, like our, our data scientists? How do we make this available to all of the other things that you might need to reflect to as well?
Excellent. org is that it? Doo Doo.
Excuse me. Okay. Check that out.
Lori, take the last word. Thanks Alan. And again, thank you so much for this partnership with Techstrong.
I think one of the things that, uh, that I love about this show and I love about this CDF, is this idea of community. And so I highly encourage you to join our Slack channel and get involved in the conversation. You can have your own hot take conversation and really kind of dig into why people think the way they do.
Why are they doing business the way they're doing business, why this is such an important topic and how it can really level up your team and your skillset. And, you know, it's all about finding the solutions that work best for your company and being surrounded by individuals that can help you get there and have these kinds of dialogues, which help you think more about what you're doing, how you're doing it, and maybe you go hard left instead of what you thought was a hard right. You know?
And so, again, the Continuous Delivery Foundation, it's a great place to have these sorts of conversations. And so, Alan, thanks to the panelists. This was so much fun.
I look forward to maybe coming back in a few months to see what's changed, what new innovations you guys are talking about, and, um, and bringing these topics again to light. Absolutely. Hopefully not a few months.
You can visit it before that. Speaking of CDF though, just a quick plug. Open Source Summit's coming up in Seattle, uh, soon.
Yes. CDF is doing things there. Yeah.
So we'll have CD Con, uh, we'll be in a room. It's two days on, um, Wednesday and Thursday, I believe. Uh, we'll have a state of the Union.
We'll have panels. We have lots of talks lined up. We'll be there with swag in the back of the room.
Lots of cool stuff to give away and lots of cool things, uh, on the agenda. Cool. Wanted to make sure we hit that.
Thank you guys. Thank you all, Andrew. We hope your child feels better.
Thank you. We, we, I think a lot of us have been through that Kids are resilient, but it just, it, you know, watching them be sick is not easy. Um, but to all of you, thank you so much.
This was a really great, lively discussion. I have no opinions on this at all, so I apologize. But, um, until our next show at CD Pipeline, keep up what we're doing.
And until then, everyone be well. Bye-Bye. In this next episode, another video series, it's our DevOps Unbound series where we discuss all things DevOps.
And in this one, we actually have another tricentis person. Martin Klaus, uh, VP of Product Marketing at Tricentis joins us, and we discussed the progress. So the, the progress that software testing has made during the rise in adoptions of DevOps and Cloud Native.
And I should mention, we recorded this live in Paris at CubeCon. Hey everyone. Alan Humel, I'm back here live.
We're back here, live at CubeCon. This is by far the busiest show floor I've seen in any cube con. I know there's 13,000 people, and I think they're all right here.
Yeah. Um, luckily the magic of technology, you're hearing us and seeing us, I hope. And because if you will hear the did of the background noise here is ridiculous.
I'm really happy We're gonna be doing a little bit something special here. Right now. We're gonna be doing a DevOps Unbound live kind of panel live at CubeCon.
We've got our very special VIP guest, Martin Cost, who evidently when he travels at events, brings his own security and, uh, Mihi Mihi and, uh, rash. These are your friends. Mitch, we're there guys.
Thanks for keeping us safe. We appreciate it. Thank you, gentlemen.
We Appreciate it. You're Good guys. I don't know, I guess Martin's a high visibility kind of target or something here, huh?
I Don't know what you're into, Martin, but I'm glad you're, you've got Security. Something outta the blacklist or something. You guys are too funny.
But, um, anyway, so this is Martin Klaus from T Tricentis. If you've watched any DevOps Unbound episodes, you might have seen Martin Aren't a few of them, but you know, it's funny, at Zoom you only see people from here up. He's actually a pretty tall guy.
Um, speaking of tall guys, to my right here is our CTO at Techstrong and Principal Research Analyst, Mitch Ashley. Mitch, thanks for being here. Always, always.
And, uh, we're here. So, DevOps Unbound, look, we always discuss everything under the sun on DevOps Unbound. But Martin, I wanted to focus today's talk a little bit on what's different about testing and continuous testing in a cloud native environment versus any other environment.
Yeah. So first of all, uh, Alan, Mitch, thanks for having me. It's great to finally meet the in person after many, many years.
It is, yeah. Uh, and it's unbelievable, the energy, the vibe, the community of Q Con, as you mentioned, 13, I think it's actually more than 15,000 people are here. Yeah.
This place is crazy. It's unbelievable. If you have not been to Q Con, you definitely to come here in person and see for yourself.
But coming back to your question, what's different? So I've been in cloud native for a long time. I've worked at Red Hat.
9. And, and so I would say if you look back over the last couple years, a lot of things have changed because, uh, one of their main objectives of DevOps was to, to bridge the gap between Devon Ops and to move, uh, you know, applications into production value in production much faster, to deliver more value to business, much more quickly than in a traditional waterfall or even an agile model. And so what happens is when you're trying to move faster and you change your process to work more efficiently, to work in small increments, then the application architecture evolves as well.
Right? We have moved from, you know, monolithic big web applications to microservices that you can update and scale out much more efficiently. Data has evolved from data rest to data in motion.
And streaming of events has become one way for data and applications to communicate with another. And so, uh, if you think through that, then you also have to think about how does that impact, uh, testing and test automation? And the whole notion of quality engineering becomes a lot more important.
'cause you have to think about quality from an architecture standpoint. You have to think about quality from an end user standpoint and, and the experiences to deliver. But you also have to think about how can you ensure quality through the development process as it relates to functional requirements, as it relates to business requirements, as it relates to performance requirements.
And a lot of companies are also dealing with security and compliance and governance. So all these things have to be considered. And, uh, it cannot be solved by tools alone.
You have to think about the process as well. And, uh, most important, I would say is adopting a tech quality first mindset and not just, you know, move things in production and see, see if it sticks. Um, but to be more thoughtful about how you're building applications, how you deliver it, and ultimately what is the value delivering to our end users.
Yeah, I I'm curious listening to your thoughts on that. You know, thinking about the people that we've interviewed and just a few of them today already, you know, it's OpenShift Red Hat folks, it's arm processor and getting more applications on, on that platform. Um, it, it, it's, um, you know, cloud native application company, it's object storage, the number of variables.
I mean, there's always been a large number of variables Yeah. To test for environments. It seems like that's even bigger.
I mean, you know, maybe exponentially more complex Yeah. In this cloud native environment. 'cause there's so many different platform.
I mean, ai, you add all that to it. Yeah, I, I agree. I think if you just walk around the SHO flight here, you'll be blown away by how many different use cases and features and capabilities that are enabled on the communities platform.
I think one other aspect that's really important to think about is, you know, develop or testing is everybody's responsibility or quality is their its responsibility. Not just, uh, the traditional QA folks. Uh, it's developers, it's project managers, it's release engineers, it's SREs and everybody else that's involved in.
But one key difference, uh, oftentimes is, and this is something that I hear a lot from, you know, my quality engineering counterparts at, you know, not just testing companies, but the enterprise. That it's not just about the happy path, you know, that you envision as a developer that your users go through. Our quality engineering is a lot about, you know, finding out what are the edge cases where things might break.
What are the environments where you, you run into a gotcha type situation, and how do we prevent that from happening? Because ultimately, uh, end users all have different environments, different browsers they log into through a mobile devices for different network configurations. Uh, they may have multiple applications running, and inevitably somebody's going to use the application wave it was not intended or designed to deal with.
And, and so that's ultimately causing quality issues. And so that's really, I think what quality engineering to be about, is to figure out how can we maximize the footprint of all the things that we're exposing the application to, to identify those weak points that we need to prevent from happening in the first place. Martin, one of the trends that I see at cloud native con con already is the, the move to platforms, right?
And, and I think it's a maturation phase of, you know, we're doing this, Mitch is heading up this report we're doing called DevOps next, where we're looking at what's next in, in the gamut of DevOps. Yeah. Right to left, left to right, you know, the whole thing.
And one of the trends is, Is Instead of cobbling together, we've got some, I feel like on the airplane, you know, I feel like I'm at the airport. Yeah, I'm ready. I gotta go board.
See you later. You're you're missing your flight. Yeah, but the think I left my wallet.
It's a TSA booth. That's right. Um, but one of the trends is getting away from point solutions that are cobbled together to platforms and almost like the Russian nested dolls, platforms of platforms.
So you can have a continuous testing platform like a T Tricentis, and that has a complete suite of tests optimized for a cloud native environment for what you're doing. And that has to fit into a larger cloud native platform. You know, that takes up my whole CICD, my whole software supply chain type of environment.
What's tricentis doing go to expand that testing platform, but also to fit into that larger cloud native? Yeah, I think the, the notion of platformization is, is one of the hottest trends in history right now. You hear about platform engineering, you hear about development platforms, you hear about, uh, quality platforms.
And the main driver for the adoption, uh, or the growth of these platforms in history is really like, what can we do to help help developers or testers and project teams stay in a flow? Because there's so many things you have to think about. There's so many distractions.
There's so many sort of other tasks we have to do during the day. And to stay focused on a particular pool request or a particular project or a particular sort of feature requirement is it's very hard. Uh, if you think about all the meetings and disruptions that you're gonna deal with every single day.
And platforms can help with that to help you simplify and automate lot of things so that there's less, uh, cobbling together that you have to do, uh, on, on your own. And one thing that is really important, uh, I think also from a standpoint is, uh, reusability and how can we enable more use cases with quality platforms? And, and, and one thing that we see a lot with our customers is that there are not just applications you build in house in enterprise.
There are applications that, that you or SaaS applications you configure and deploy or enhance, uh, or an application you just use. So you'll see, we'll see the whole gamut of applications that you deploy and configure, uh, that you use across the enterprise, but then also applications that you're extending and building yourself, and how can you deliver an end-to-end quality automation platform that supports all these use cases between enterprise IT back office applications like Oracle and v uh, business applications like Salesforce and ServiceNow and many others, as well as the custom applications that you use internally. But that can also be client facing, right?
And what we found is that a lot of customs are looking for ways to, uh, standardized process through a quality engineering framework, but they also looking into standardized tools and platforms, so that enable quality engineers across many different teams to work together with their developing counterparts to release applications faster. And so that's kinda like what we're trying to do to really focus on usability and the end user experience, but also make it easy for people to get started with functional automation, but then expand it to, you know, data testing for example, or load testing, mobile testing and other things, uh, that, uh, they may need to do for the particular application that they're trying to release. It really makes the case platforms are just for infrastructure.
Yes. No, that's part of it. But it's platforms up the stack and Well, it's horizontally and vertical Exactly.
Is the Key to it. And like I said, it, it's like that Russian nested dolls thing that's platforms within platforms and, but again, For Dune, you gotta make it a dune plans within plans, Spirals within spirals, Yeah. Or think about this as layers, right?
Like the, the networking layers of, you know, L one through L seven might be one analogy to think about what you doing on the infrastructure layer, what you're doing at the application layer, at the testing layer, and so forth. Well, at the end of the day, the spice must flow. Let's see.
Sleeper must awaken too, but, um, so can I ask the AI question? We haven't talked About ai. Oh, it's, it's enough time.
Go ahead. We Have, we have an upcoming live session on testing AI in your applications. I'm curious your thoughts, and I wish I had the, the data on it.
We'll, we'll, we'll get that out to everybody. What are your thoughts about when you incorporate ai AI into your apps? There's models, there's data, there's training, they kinda have their own flows or, you know, even more so than just a database or data source.
How do you think about testing in a, in a cloud native world that has AI part of it? Yeah, that's a great question. I think that's, I, Let's answer that in five seconds.
Yeah. The whole industry is sort of, uh, thinking about that right now. Because on the one hand, today, for example, we saw many great use cases for AI models and for them to production and, uh, you know, using LLMs to summarize a live fixture of what was being seen.
And, and so also we're seeing, you know, the use of AI from a co-generation standpoint, right? And there was a recent article from, you know, Joe Vanai who mentioned that, you know, we've shifted the problem, you know, from development to qa and what used to be, you know, three developers, one qa, it's now one developer, and three QA is because, uh, developers can now generate so much more code using AI tools. And now that puts the burden on the, on the testers to verify, you know, the increase in credential security, uh, flaws and things of that nature that are being introduced, uh, if the code is not being tested and validated, but generated from some random source.
So that's one aspect. But I think the bigger question in industry right now is how do we test the validity of the results of an AI model? And if the summaries and, uh, all the things that an L one can generate are, uh, meaningful and they're not, uh, they're free of hallucinations and things of that nature, I think that's a great use case for explore are testing.
Um, I think there's also an opportunity to actually use other LMS to test the output, you know, from LMS and see if there's a consensus around among LMS on the results. But at the end of the day, um, you know, uh, you still need a human in the loop. Uh, you cannot, we're not at this point yet where the human is completely eliminated from the FS cycle.
And as the, the technology matures, I'm sure there's gonna be more opportunity for automation to test ai. But for now, I would say we're still very much in sort of the, the good old, you know, you know, exploratory testing, even trace back to the data, you know, how the s came up with certain results. But, uh, you know, that is still also like the big, the big problem for an administrative practice.
Makes sense. No doubt. I mean, we could stay here and talk cloud native and AI and well, Everyone else here is Testing.
Actually, AI was the star of the keynote today too. Yeah, That's what we heard. Anyway.
Hey, Martin, I want thank you for stopping by. I can't believe you came all the way to Paris just to do a cloud native, But this one session, This is great DevOps on thing with us commitment That was nice of you. That's commitment.
Yep. But seriously, thanks to you and Tracy. This is always, we're gonna be back to our regular schedule of DevOps Unbound, I guess, when we get back in another week or two.
And, but until then, we'll be here live all week, covering what's going on at CubeCon. Many thanks to Martin Klaus and Chiantis Mitchell, Ashley and Alan Shimmel. You're watching Text On tv.
Next up, we have another video show. And this time it's our Techstrong women and host, Jody Ashley and Tracy Reagan have one of my favorite people on Caroline Wong, who's chief Strategy Officer at Cobalt, and they do a deep dive on cybersecurity, on Beyond Check out Techstrong Women. Hi everybody.
Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech. I'm Jodi Ashley, executive producer at Techstrong, here with my co-host, Tracy Reagan, creator, and CEO of Deploy Hub and Linux Foundation enthusiast. Pete, before I introduced today's guest, I wanna give you a quick update about what's happening here at techron.
Be sure to register for Textron Con 2024. It's happening on April 3rd, so you can still get in there if you wanna, if you wanna attend. Um, also, we are launching a really cool and exciting virtual event called the Artificially Intelligent Enterprise on May 21st.
It's going to be a 24 hour global event, so you won't wanna miss out. com and register for all of our events. And we love sponsors, we love speakers.
So keep your eyes open and you'll be able to sign up to do that stuff. tv every day for amazing content shows and interviews. Hey, Tracy, what's on your mind today?
Well, I think a 24 hour kind of follow the Sun conference on AI is pretty interesting. I know it's gonna be fun. I'm looking forward to it.
Absolutely. So, you know, today I wanna talk about, I often talk about Jenkins, but I'm gonna talk about it again because it continues to be a prime tool that companies, enterprises around the world have used. And this happened in late January.
Um, about 45,000 Jenkins instances were exposed to an online vulnerability, uh, that allowed them to get remote code execution, or depending on your, your security settings, basically gave you a, a access to the command line, and to be able to get access to certain, uh, files, 45,000, um, servers. We, we, everybody asked to stay diligent, right? Um, and tools like Jenkins, while everybody works really, really hard to make sure they're secure, you never know when a vulnerability's gonna pop up like that.
So I just wanna put it out there. It was out, you, you might, uh, look for it. It's, uh, it was published back in, uh, late January, and it really talks about the exposure and why it's important to fix it.
So I'm putting it, putting it out there for all you Jenkins users. Look to see if you have that particular version and if you have an issue. All right.
Thank you, Tracy. All right. I'm so excited.
I've been trying to wrangle this lady for quite some time, but she is very busy. Um, our, our guest today is Caroline Wong. Caroline, tell us about yourself.
Thank you so much for having me. I am delighted to be with you two today. My name is Caroline Wong.
I'm the Chief Strategy Officer at Cobalt. We're an offensive security testing company. Um, I've been working in cybersecurity since 2005, starting off on security teams at eBay and Zynga.
Um, in 2011, I published a book called Security Metrics, A Beginner's Guide, uh, in 2022, that book was inaugurated into the cybersecurity Canon Hall of Fame. Um, I teach courses on LinkedIn Learning, and I host a podcast called Humans of InfoSec. Very interesting.
And I know that you are passionate about, uh, teaching and talking about security and cybersecurity at work, uh, which is a really interesting topic because no matter how, how hard we all work to secure the supply chains to secure our environments, somebody can put an use there, pet's name, which we probably all do for, for a, for a, a password, and all of our hard work is gone. So why don't we talk, start today about talking about, you know, cybersecurity at work and, and how people should approach cyber, what we should know as we we do our daily work. Yeah, first I just have to say, Tracy, I love that you opened up today's session talking about a vulnerability in Jenkins.
This is something that I get really excited about because the thing about software is that it's vulnerable. And unless we're proactively security testing it, unless we're proactively installing fixes, the vulnerabilities are just sitting there waiting to be exploited. And I think that the thing, the, the main concept that I try to communicate in cybersecurity at work is simply that everyone's getting attacked all of the time.
All of our organizations are under attack right now. We're just all being attacked, you know, and if folks could understand this and understand that it's something that happens all the time, every single day, and not just sort of a random occurrence, or if you're doing something super important or if you have some sort of super confidential restricted information, everyone's getting hacked all the time. And that being said, my sort of, first I would say there's really three things for most people to keep in mind.
And this is what I say. If I'm talking to my 8-year-old daughter, or my 7-year-old mother-in-Law thing, number one, look out for fishing. And if something seems too good to be true, it very well might be.
And just take a screenshot and send it to me and I'll check it out. Um, but, but whether, whether or not you're my literal family member or not, you know, send it to someone you trust and just ask them to take a look at it. Um, and make sure that if there's an opportunity to verify it via some other route, for example, you know, you get a text message and it claims to be from a shipping company, you know, go online, go to their real website, call them up and ask about it.
Um, so number one, we are all getting phished and social engineered all of the time. Uh, learn to expect it and learn how to, uh, question it. Thing number two, use multifactor authentication.
I'm not saying that it's okay for all of our passwords to be our dog's names, but if it were, and we had two factor authentication, authentication, then we'd be in such a better spot. Um, and these days, you know, that kind of thing is really so easily accessible. Um, so definitely for online banking, definitely for email, really for anything that you really care about, just turn on my multi-factor authentication all the time.
Do you need to do it for Netflix? Maybe not. Do you wanna do it for Amazon?
Probably. Um, and then the third thing, and this is really geared toward sort of everyone, all of these tips are geared toward everyone. Update your software.
I know how annoying it is, and when it takes me 20, 30, 60 minutes of time where I am unable to access my laptop because Apple has released yet another OS update, by the way, is it just me? Or do they seem to be coming in really, really frequently? But you know what?
I don't care how frequently they come in, you gotta prioritize it because hopefully, even if you don't prioritize it, your organization's, it security team is actually making it happen. But what's gonna happen if that's the case, is it's gonna be a Friday morning and you're gonna be on an important call, and all of a sudden your computer is just gonna start installing and updating, and then you're, and then you're, you know, it's gonna be really inconvenient. So just pick a time, you know, maybe it's the end of a workday.
Um, and, you know, you're about to go take a walk. You're about to make yourself a cup of tea. Just install the update, do it for your os, do it for your laptop, do it for your smartphone.
I really think that between those three things, if I could only tell folks three things, uh, those are really it. Um, but I will give a little plug for my cybersecurity at work course on LinkedIn learning. Mm-Hmm.
Um, if anyone's interested in viewing that course, uh, you can find me on LinkedIn and on my feed, I've actually got a featured post, uh, where you can watch that training, uh, at no cost to you, even if you don't have LinkedIn learning. Um, and one of the things that we did that was really fun was we did a couple of scenarios. Um, so we tried to make it fun.
We tried to make it engaging. Uh, I like to think that it is, uh, pretty engaging and pretty fun as far as cybersecurity training goes. I'm absolutely gonna go check that out.
Um, and you know who my husband is. So the two factor authentication thing is been a thing that I hate and drives me crazy, but nobody makes me do it. So it's attached to everything in our house already.
But getting younger people in their twenties and thirties to update their computers is such a nightmare. Like, we have kids that are working in, they have a max, and my daughter does. And how often she'll be like calling, like, I can't, my, I can't work today.
And Mitch will be like, well, do you need to do some updates? And, you know, it's six months old and you're like, so I have another question though. When you talk about, um, companies trying to hack and security breaches, you said that a lot of them sit there waiting for the moment.
How much of that happens and how long, you know, how many people create stuff and it just sits there for three, four months waiting? How long, how often, how common is that? So here's the fundamental problem.
Software and the internet, the power of software and the internet, mm-hmm. Is connectivity. The internet started out universities trying to share information with each other.
We had atmospheric scientists trying to share large amounts of data. The internet was not built to support global electronic commerce. It just wasn't.
And so security is not inherent to software. Security is not inherent to any internet protocols. In order for something to be secure, it has to be secured on purpose.
And the best way to ensure something is secured is to test it, go after it with an attacker mindset, the offensive security mindset, test that software, find the vulnerabilities, fix the vulnerabilities. Um, it's really the only way. And what happens is if you're not even looking mm-hmm.
The vulnerabilities are just sitting there. If you are looking, then at least you know where some of it is, and you are in a position to address it if you choose to. Now, there are trade-offs involved, right?
Because security testing costs money and addressing security problems, cost, resources, and money. And this trade off is where sort of the security complexity lies. Mm-Hmm.
Um, but on one hand it's actually simple, which is to say, do technical security testing, go and find those vulnerabilities, and then work with development teams to go and get it addressed. And that is part of the bigger problem because we are finding vulnerabilities. Vulnerabilities are now being found at, at a, uh, a rate that we are, are not used to.
Mm-Hmm. Because now we have vulnerability databases. We have tools that are sta scanning for vulnerabilities.
We're reporting them. Um, and you, you know, of course, Jody said, I was gonna talk about sbu. I'll have to, I have to kick this one in.
Um, if you don't have an sbu you don't necessarily know the, uh, vulnerabilities blast radius, and you don't know what the remediation step should be. So I often, uh, talk about the, the future where we have a FEMA like response for vulnerabilities. Well, I don't have to wait.
If somebody's found one, get it, get it communicated. We lack collaboration in this area at a global level. And I've spoke to some people that says, well, we don't want people to know where those vulnerabilities are, because then hackers will know about it too.
But the sooner we know about 'em, the sooner we can shut the door. Oh, they already know. They already know.
They already know. That's what I, and we don't, the Vulnerability database is public to everyone. Everyone, You're a good person or a bad person, you know, it is equally accessible.
And the bad person is probably more likely to be hunting around the vulnerability database to find out the ones that they want to go and attack. And the good person is the one trying to get software out, right? They're the ones working and trying to get their software out.
They're not thinking about looking at the vulnerability database every day. And if you don't, if you, if you don't know where those vulnerabilities are in your, in your, your software supply chain it from this, from a coding perspective, it's hard. It is hard to get those fixes in.
And then the remediation is not shared. So somehow the industry's gonna have to get to a, thinking about this in a FEMA response. Now, you talked about it, I think you talked about it.
Uh, um, you said two terms. One was the hacker's mindset and an offensive mindset. Why don't you talk a little, get get a little deeper into that, so maybe we could better understand how to solve the cybersecurity problem?
Yeah. In my experience talking to hundreds, thousands of security and development practitioners throughout the year 2023, there was a really big theme which emerged. And the theme which emerged is everyone's experiencing layoffs and everyone's experiencing budget cuts.
And what does that mean for cybersecurity practices? It means there's simply less to go around one of our limited resources we had before to allocate towards managing different risks that's now smaller. And so I would like to put out the idea that when thinking about a cybersecurity program, you can think about two domains.
One which is defensive security controls, and one which is offensive security controls. Multifactor authentication is a perfect example of a defensive security control. One that I think is really important to do so is updating your software.
But an offensive approach says to your point, Tracy, about attack surface. Do I even know what my attack surface is? You know, am I aware of any sort of shadow domains, dangling domains?
You know, what's out there that actually belongs to me that I'm responsible for, that I may not be looking after? And once those assets are identified, security testing, whether that is scanning, data scanning, whether that is manual penetration testing, taking a look at your organization's digital assets and considering what it looks like to an attacker. Um, and, and, and my thought is by doing this, organizations have an opportunity to focus their very limited resources on addressing the items that come up in that offensive security analysis.
Cobalt actually just published a report called the Off sec Shift Report. Uh, and it contains a bunch of data, um, from thousands of, uh, security and development, uh, practitioners, uh, that talk about how budgets are shifting and organizations are investing more in offensive security for exactly this reason. And, you know, this concept is new to me.
This a concept of offensive. I think most of the things that I think about are, are defensive, right? Beyond just knowing what digital assets you have to manage.
Is there other ways, you know, I think offensive, I'm a hockey person, you know, we have a goalie, we have, you know, we have defensive players. Who are the players in that kind of, that offensive world? Hockey feels like the right analogy, very physical, you know, boom, boom, right?
It's not subtle. We have, we have forwards and we have our wingers and what are forwards and wingers doing right to go and score? What are they up to?
I, I think, you know, you've got sort of a few classic categories of attackers. You know, you've got sort of the really big scary ones, you know, nation states, um, but you've got others. You've got potentially, um, you know, competition, um, search, searching for intellectual property.
Um, you've got your sort of typical, um, you know, spray it all type of scammers who are just looking to make a buck any possibly way they can. Um, certainly ransomware, uh, is a big way in which people and organizations are being exploited. Um, and these days, the thing about being a hacker is that hacker tools and approaches are not that expensive.
You can buy a password cracking system and, and the storage required for it for less than $50. Um, it's just not that hard to do. The bar is just not that high, so it doesn't require a lot of money.
If you've got an internet connection and some knowhow, um, then, then there's a lot of power, uh, on the attacker side. Um, and I think as organizations, what we really need to do is we need to say, okay, what does our attack surface look like? What is our critical data, our critical systems that absolutely need to function?
Let's do a bunch of security testing and let's make sure that the vulnerabilities that are found are fixed. And depending on how frequently we're updating our software and everyone's updating their software all the time, we need to be testing those deltas on a regular basis. Um, this, I think is a very effective, uh, and efficient way, uh, to, to spend cybersecurity resources And boy, in our, uh, kind of our geopolitical environment right now.
This is really important. Uh, absolutely topic in Russia and North Korea and Iran, right there, those three countries are, you know, they are spending, they're paying people to spend time to hack all of us. They're serious about it.
This is a serious game to them. It's not just a, uh, a discussion we're having about trying to secure our environments, right? Yeah.
Serious. We're not doing this for kicks, you know, we're not doing this 'cause it's a nice to have. We're doing this because attacks are happening all the time to all of us.
You know, I think it's so interesting, um, some of the most recent SEC, um, you know, activity with regards to SolarWinds. Um, and while I don't personally, uh, know that I would go about it in exactly the same way as the SEC is doing, you know, I do have a belief that what they're trying to accomplish is they're trying to put more of an emphasis on the idea that security is really not optional these days. It's really not optional.
It really should not be optional. Um, and I, I, while, uh, there are specifics, uh, about, uh, what's going on, uh, that are not again, necessarily the way that I would personally go about it, um, I do see it being elevated, uh, to a different level of conversation. And for that, I think it's very, very appropriate.
Yeah. And I think that the Biden administration, it made the right move to at least have the SBO m discussion started saying, Hey, if you're gonna do business with the government, you better report to us what open source packages you're, you're consuming. Because we may not wanna trust those packages.
But I don't find that that kind of data, even though we have it, is being consumed and acted upon. Yeah. I think, I feel like, I feel like it's still fragmented, still not, um, it's out there, but, but, you know, uh, great, you know, SBOs, so far so good.
So what, right. The, the, one of the really interesting things that we have not figured out as an industry is how to effectively communicate technical security posture to each other and even SBO m information to each other in a standardized format. Every organization does it in a different way.
And that means that every time you interact with another organization and any given organization has got to have probably like 75 vendors, you know, larger enterprises are gonna have hundreds, thousands of vendors. Um, but without any sort of standard, um, or, you know, in the case of our industry, actually too many darn standards to choose from. Um, you know, the, the reality of, you know, a person on that security team who's in a vendor risk management role, you know, they've gotta, they've gotta sort of sift through and figure out and interpret, you know, each and every single one.
Um, so there ends up being just a tremendous amount of manual work involved, uh, if folks wanna do it, right? Yes. There is a tremendous amount of toil right now in that, in the, in solving the cybersecurity puzzle, a tremendous amount.
And I think we will face that for the, at least the next five to six years. Even in, you know, my world, you're, you're kind, you're in the, you're in the pen testing business and I'm in the DevOps side. If we think, if we go back to our Jenkins, um, I, I repeat this many times 'cause it's a good thing to remember.
According to CloudBees, they track about 90 million workflows a month. Uhhuh 90 million. Now, I don't know if those are a duplicated workflows, so let's just say it's, you know, it's 9 million workflows a month even so are being executed thousands times, times even there even, yes.
It's, it's a humongous number of DevOps pipelines that need to be updated to have security built into it. And this will be a challenge for us because there's a, an extreme amount of toil in being able to achieve that. So that, uh, being offensive one way is to build it in there, right?
The other way is maybe we talk about zero trust. So will zero trust get us out of this problem and saying, we're gonna start blocking anything that comes from Russia or North Korea or Iran. We're gonna just block them completely.
You know, where are, where are some big wins? Do you have any ideas or have you thought about that? So I do think that there is a lot of value that comes with zero trust, but I don't think it's possible for zero trust to be fully automated.
And what happens is the manual work just gets shifted. Mm-Hmm. From my perspective, in an ideal zero trust model, you know, the most important stuff has a really big fence around it.
And if someone tries to get in some human with their judgment and their opinion is coming in and saying, yes, let them in or no, do not. Um, and that times 9 million ends up being, again, an extraordinary amount of work. Um, I have a kind of a crazy idea that it would be fun to, uh, share with you, uh, on this, on this, um, session today, which is, I happen to have a garden and I observe the cycles of that garden throughout the season, you know, and there's times when, uh, the seeds are just in the ground and there's times when the plants are growing and there's times when they're blooming and there's times when they're wilting and it's, and it's fall and it's turning to winter.
You know? And I actually think that software has this sort of cycle that it goes through as well. And there's a time when if software is not being looked after properly, maybe it should be sunset.
But what we do is we treat all software all the time, like it's in full bloom. And I think that's actually just not appropriate. I think it's, I think it's actually just a fundamental misunderstanding.
You know, when we work in tech, right? People who don't work in tech, they just assume that everything software works is supposed to work absolutely perfect all the time. And the reality is, some of us know that some software is being paid an incredible amount of attention to, and a lot of other software people aren't paying attention to it.
It's not being updated. All sorts of legacy stuff, all sorts of old integrations. Um, and so I think it would be really interesting, uh, if we had a way to evaluate, is it time to sunset this particular piece of software because it's actually introducing more risk than value.
Really? Interesting. That's a really interesting thought.
You know, what can replace it? What's, what's new out there? And boy, is it hard being from a, having a software company, it can be really hard to get customers off of old versions.
Totally. Coming back to your point to say, upgrade your software, please upgrade your software, because we may know there's vulnerabilities out there, but we can't get them get, you know, get folks to update their software because it, it, it may take some time. It may bring down, you may, they may need to do a freeze for, you know, an hour and a half.
It may deny service for some period of time, but boy, isn't it, IM important. And I think the better we get at from a software perspective and who does as a commercial vendor of software, the better we get at being able to have SaaS environments where we are managing the platform and updating this stuff for them. Yep.
Uh, is ultimately going to be, you know, another way to be offensive in our, our approach to cybersecurity. Because what we're doing, it's not necessarily defensive. What we're doing is what're pushing away.
We are, you know, we are going out after our criminals, right? We're going out after them and saying, no, no, no, no. Yeah.
It's really, it's really, it's really a proactive approach, you know? Um, I think that businesses have an awful lot of decision-making power that affects an organization's security posture. Um, a funny little analogy that a friend of mine used to talk about was, he would say, you know, if you have a, and that toddler is running around with a pair of scissors, the best thing to do is to take the scissors out of the toddler's hands.
You know, but how often do businesses and organizations just allow toddlers to run around with scissors? Because there's A lot of toddlers running with scissors. There's just a lot, there's a lot of toddlers, scissors, you know, and, and, and, and it, and it is a business decision.
And there are gonna be trade-offs. That toddler is gonna throw a big temper tantrum and you're gonna have to deal with it, you know, but you're gonna have mitigated the risk. And so I think this is both the complexity, um, as well as what makes cybersecurity super fun, uh, is all these different trade-offs and, and really having a lot of the time no right answer.
So when you talk about zero trust, um, just to backtrack a tiny bit, and you talk about all those, these instances, whether it's 90 million or 9 million or whatever, how much of, of all of this we're talking about, I'm just gonna throw it out there. Is AI going to help with 'cause Right. One person can't say, let this person in block this person.
How much, I'm sure companies are already doing it, but I would assume AI is gonna play a huge part because it can do all the massive work and then a human can evaluate a smaller subset of that, right. As far as being able to manage it, I just, another amazing, you know, application for ai. Absolutely.
I, I completely agree with that concept. I'm actually currently working on a new LinkedIn learning course that I believe will launch sometime around August, 2024. And this particular topic is about artificial intelligence and application security.
And I do think that we have an opportunity for any bit of manual work that we do, whether it has to do with software development, whether it has to do with cybersecurity activities. There's a spectrum of how much can be taken on by ai. And at each stage of that spectrum, there's gonna be an associated confidence level with how well we think they're gonna do it.
It's gonna do it, you know. And so there are gonna be basic, very well, well known, often observed, often repeatable patterns that can be detected. And AI can even get to a point where it's making this the decision, choosing the next action.
You know? But as, as soon as we move farther down that spectrum and things get to be a little more unusual, a little more customized, a little bit more of an edge case, that's where I think we have an opportunity to focus more of the manual effort. Um, and so I don't happen to think that, um, you know, AI is gonna take all of our jobs.
I I do think that it, that it will dramatically change the way in which we work. You know, I said to, um, my 8-year-old and my 11-year-old niece the other day, I said, here's an AI application that I want you to download on your iPad, because I want you to get used to using AI right now. Right away.
I said to them, anytime you would go on Google and ask Google a question, ask AI instead, because I would love for them to sort of naturally develop this capability for writing AI prompts. Absolutely. I think it's a really, really good skill to learn how to, you know, chat.
GBT is teaching us all that. And I, I keep telling the story. I, I was waking up with my eyes totally swollen for like, three weeks in a row, and I couldn't figure out what was going on.
So I was working and I just asked, give me a diagnosis for swollen eyes and what's the symptoms? And the first thing that came up was dehydration. Wow.
Yeah. And so I was like, okay, I'm gonna drink 60 ounces of water a day. And in three days my eyes stopped being swollen.
So I actually used it as for a medical condition. Well, Tracy and I have this conversation all the time because it's AI terrifies me, and she's like, AI is the coolest thing ever. It's awesome.
So I'm, she's helping me. Like today I am like this, you know, another example where AI is gonna be really helpful and yes. Another reason humans aren't going away.
You know, the whole, the whole concept that it's gonna, you know, there are gonna be some shifts. There's everything with, you know, with progress comes change. Right?
There's always gonna be a shift. And that's why people have, we retrain entire groups of people to do different things. But it's, it's that way with everything.
AI isn't any different, but it's cool to, I'm trying to find the good, find the good. I'll tell you what, Just think this way. Think about it this way, Jody.
We, I was raised with encyclopedia, Well, I'm not Encyclopedias went away. Encyclopedias went away when the internet became popular. 'cause you could find answers through the internet, but people's jobs didn't.
Yeah. AI is the same thing. It's just a different, we have a different relationship to data and it's going to be displayed to us in a different way.
It's a complete shift, but it's the same thing, right? It's just, it's the modern day encyclopedia. Well, and Jody, I'll tell you what, there are two fundamental reasons that I believe AI will not and cannot take over all of the work that we do.
Thing number one is garbage in, garbage out. Right? AI works on data.
And unless you have an enormous perfect data set, your results are never gonna be exactly right. Um, our data sets are biased. They're too small.
They're, they're wrong, and They're shifting. Yeah, exactly. Exactly.
So that's thing number one. The other thing is AI requires processes and algorithms. The AI does not know how to choose which process or which algorithm to run unless a human tells them.
So, right. And if, you know, because I work in the area of application security, I think about things like static testing and dynamic testing. I think about the differences between network security vulnerabilities and application security vulnerabilities.
And if I have an ai, and that AI is designed to work through a workflow, having to do with finding network security vulnerabilities, and I point that at an app, it's not getting, gimme the results I want, we need people to dictate what type of process, what type of algorithm. You know, it's like saying, um, you know, to an automated, uh, you know, chef robot, uh, you know, make me a pumpkin pie, you know? But if you, if you put in the cheesecake recipe, you know you're not gonna get a pumpkin pie.
Um, and so there is, that is An amazing analogy. That is the best analogy ever. Maybe you'll Get a, you'll get a cheesecake, pumpkin pie.
There you go, cheesecake. You'll probably get something delicious, but you're not. Get a pumpkin pie.
You'll not get pumpkin. If there's no pumpkin in the recipe, you're not gonna get a pumpkin pie. That's amazing.
I'm sorry. That was a great analogy. I love that.
I'm gonna steal it. So before we run out of time, this is a question I really love to ask our, um, our guest, and tell us what brought you to technology. You're passionate about it as I am and as most of our, our guests are.
You know, how did you get started? Was there a woman in your life that said, Hey, you need to go into tech. Give us, give us a little bit of insights about your background?
It was my dad. I am the daughter of Chinese immigrants to the United States. When I was a little kid, my dad said, you know what, I'm gonna buy you Mavis speaking, typing software, because my dad was an attorney, you know, and he had a really great secretary who typed on his behalf, you know, but he was one of those one finger typers and said, Caroline, in your lifetime, it's gonna become really valuable for you to learn how to type quickly.
And so I learned how to type quickly at the age of, you know, 10 or something. Uh, and when I was about to go to college, he said to me, Caroline, what do you wanna study in university? And I said, well, I love dance, so I'd love to study dance.
And I think psychology is really interesting. So I'd love to study psychology. And he said, you're gonna study engineering and you're gonna study the hardest engineering at the top school that you can get accepted to.
And so I went and I studied electrical engineering and computer science at uc, Berkeley. And that was that, you know, and I, it was just, it was just the culture of the family that I happened to grow up in. Um, and while, um, you know, I had all sorts of, I would say behavioral and psychological responses to my father's, extremely high expectations of me, um, he did instill a confidence, um, and a kind of like, maybe I don't know how to do this right now, but I can figure it out n about it.
Um, and now at this stage in my life, you know, as a mother, and I'm looking at my kiddos and their lives are filled with technology, and I just want the world to be a safe and a happy place. Mm-Hmm. I just want my kids to be able to use their computers and go on the internet and play their games and be safe and be connected and create without having to worry.
That's what I want. You know? And so, um, I feel so grateful, um, that I'm in this field, uh, and that I get to do this type of work.
It's interesting almost all of us that we, not all of us that are in this field, we had a parent or someone who really was forcefully directing us into it. It wasn't something that we saw that we should do for naturally, like a little boy might. Right?
And it's different now. We had to know somebody, say, go for it. It's Different now, you know, these days, you know, I don't know exact statistics, but when I studied computer science in college, it was not typical.
It certainly wasn't typical for a woman, but it kind of wasn't typical. Anyway, you know, these days I think there are so many more computer science graduates than there were at that point in time. Um, and so these things do change.
Um, but I am, uh, I'm extremely grateful to my dad, uh, for, for pushing me in that way. And I hope that the STEM programs that are, you know, starting to really flourish throughout the u the us in particular, uh, can serve as your dad did to you can serve to other young girls who may not have a parent that said, you know, like my mother did, Tracy, you can't draw a straight line. You do math like crazy.
You probably should go into some field of engineering. You probably shouldn't do, you know, history is great, but it's not gonna get you the job you want and go do math. You know what else is crazy though, is we've had these conversations.
And Tracy, how many times have we asked this question? And it started out with, I played an instrument. I, I like to do drama.
I like dance. So much of what we don't acknowledge is that the arts are so important. Um, just as an example, my daughter's now an actress.
She went to the Denver School of the Performing Arts here in Denver. It's a public school open to any kid who auditions and gets in 12 different majors. We also have a STEM school, the School of Science and Technology.
Do you know which school is on the, uh, US world and report top schools and gets the best standardized test scores. The School of the Arts beats the science and technology school every year. 'cause they have art in their curriculum every day.
And the kids that just go to the, the science schools don't. But I hear so many of, so many of the, of you guys who, who we've interviewed have an art artist in them of drawing or dancing or music. And it so stimulates everybody.
And it's so important and needs to Be there. I think you, you have to have both, right? You have to be do you have to, you, you can't just copy everything.
You have to have Both sides of your brain working. You have to have both sides of your brain working. So I th that, that is why women are so, uh, perfectly kind of positioned to be in technology.
And one area that if you're listening and you're a young college student and you're a woman, think about going into cybersecurity. It is going to be a hot space, and it's gonna be around, it's gonna be, everybody's gonna be pushing it for at least the next five to eight years. So consider going into cybersecurity or any area in defense.
Yeah. Get your, get your daughters in coding classes, our granddaughter's middle school. And she, she loves it.
She thinks it's fun and they do it in school. And she, she thinks it's the coolest thing. Her brother, not so much, but you know, that's okay.
Good. That's great. Exactly.
Well, I think we're like right at the end of our window here, but Caroline, thank you so much for being here. I am so excited that, um, you got to join us. Um, I can't wait to see you at RSA in May.
And, um, we just really appreciate you taking the time. We know you're a busy lady and your time is super full, so we appreciate you being here with us today. Trace, you got anything?
No, but thank you Caroline, for a fabulous journey into the world of cybersecurity. This Was so fun. Thank you both.
Great. Well, thank you for being with us. Hey everybody, that's, uh, a wrap on today's episode of Techstrong Women.
Be sure and stay tuned. There's a lot more great content and programming today, so be sure and watch and we'll see you next time on Techstrong Women. Bye.
Hey guys, this is JJ Manila with Mitch Ashley co-host of CISO Talk where we have engaging bite-sized conversations for current and next-Gen CISOs. You know, we have some of the best conversations on CISO talk with some of the greatest talent in security people like Andy Ellis, who talked to us about optimizing security strategies and how to navigate the boardroom. Lisa Bradley came on and talked about vulnerability management bug bounty programs and why SBOs aren't the solution to all your software security problems.
Steve Reynolds was also another great guest, and he talked to us about what not to do when a security incident happens. The What not to dos are great, but we also had Eve Mailer and Steve bitten on talking about security, uh, and third party software, SaaS applications, and weaponizing ai. So go ahead and join us for the latest episode of CISO Talk.
You can find us by going to Techstrong TV slash CISO talk. This next interview is Mitchell Ashley, our CTO and principal researcher at Techstrong Research. Mitch speaks with John Capello of Nasuni and Adrian CIA of Tetra Tech, and they discuss Nas Sunni's, uh, NAS Sunni's Edge for Amazon Simple Storage as three availability.
And which by the way, it's a cloud native distributed solution that allows enterprises to accelerate data access and delivery times while ensuring low latency access that is crucial for Edge workloads. This is Techstrong tv. Hi, I have the great pleasure of being joined by a couple gentlemen here.
We're gonna be talking about hybrid, uh, cloud network hybrid storage, you know, as we live in this world of hybrid clouds, how do we manage our data across all those environments? I'm joined by John Capello, who is with Nasuni. I had announcement recently that we're gonna be discussing and Adrian, cia and I believe Adrian's a customer, right?
Or user of the technology, uh, working with Nasuni, so, uh, with TetraTech. So, uh, John, why don't you start off, just tell us a little bit about your role in the company and, uh, overview just of what Nasuni is, and then Adrian, if you just mention what you do. Sure.
I'll start off with a, just a, a quick intro. I'm John Cappel, I'm Field CT at Nasuni. Um, I get the pleasure of having to work with a lot of our largest customers.
Um, TetraTech being one of our, um, uh, of our biggest customers that really pushes what we do at Nasuni and really takes advantage of a lot of things that we do at Nasuni. Um, a lot of the innovations that we've been working on recently, um, I've been lucky to be able to engage TetraTech on that. Um, I also work with a lot of our cloud partners, so, um, a key part of our solution is that you have an object storage underneath that you have, um, that you place Nasuni on top of.
And so we work with all of our major cloud partners, AWS, Amazon being, um, obviously one of our biggest ones too. Um, but I'll hand off to Adrian for, um, intros, and then I'll say a little bit about Nasuni after that. Great.
Sure. So, um, I'm Adrian cia, um, with Tetra Tech, uh, part of the IT system engineering group. Uh, and, uh, my main involvement with Nasuni was, um, designing the architecture and, um, doing the project management for the transition from the typical Windows file systems to Nasuni ecosystem.
Very good. Well, tell us about the announcement. I think it's relative, relative to S3 and AWS environments.
Sure, yeah. So, um, uh, just to start, lemme kind of, uh, set the table about like what Nasuni is. Um, now I'll talk about the fact that we've added S3 as a protocol on top of our massive file system that does a lot of really good things for us.
Um, so number one, you know, Nasuni really is a, as Adrian was talking about, kind of the, the evolution of file infrastructure within the enterprise. So think of it as a modern approach to how to store your unstructured data. Um, up to this point, a lot of customers have been storing it on nas on, um, file servers.
So whether it's a Windows file server, whether it's something like, um, you know, a NetApp or an Isilon, um, those are all fantastic data center based solutions for storing data and storing unstructured data. But Nas Sunni came along and we said, what if you could have all the power and the benefits of a nas, but you were backed by some kind of, um, cloud scalable solution. Um, so what we did was we built a, um, infinitely scalable versioned file system on top of object storage.
So you as a customer, you've got access to your AWS account or an Azure account or Google account, um, or maybe you have a private object store. Um, and we, um, allow you to then create a file system within that object storage within your own, um, your own tenant. And on top of that, you'll, um, then be able to access your data through a software defined layer of these edges that we call them.
They're basically like, um, uh, look, look and feel a lot like NASA's. So for us, you know, we're taking a different approach to how you manage file infrastructure because we have a really, you know, unbelievably scalable foundation to it with an object store. Um, we have built in security and how we actually encrypt the files from edges and move them into the object store.
But we also have a versioning capability that is, um, really unparalleled in the industry. Um, people talk about restore points or access or, um, you know, backups or, um, uh, you know, uh, snapshots to be able to restore their data. And those are usually hundreds or thousands of different restore points.
We have literally millions to billions of restore points because you can restore files and folders. So security for us is built in, data protection is built into us. And then the fact that it's a, a software defined model where the access points are not the object store, that's not how you get to your data.
You're actually getting it through these edges, these, um, software defined appliances that live as virtual machines, really, wherever you can deploy a virtual machine. So up to this point, those edges have been speaking files. So it looks like a nas, acts like a nas, I can write to it through SIFs, write to it through NFS.
Um, but what we just announced is we've added a new layer on top of that, a new protocol in which you can get into that, uh, file system, and that's using the S3 protocol. So, um, what you don't see anywhere in the market today is the ability to have this massively scalable file infrastructure, or let's just call it now a global namespace. I can write to it through cs, I can read to it, um, through NFS.
And now that same namespace, without migrating any data, is now available through S3. So in some ways, you can think of what we've developed, not just as a way of adding protocols into your file system or extending out the global namespace, but now up to this point, what you have thought of as almost like a, um, like a data lake, um, and object, um, based architecture for storing unstructured data is now available as caches, wherever you wanna put those caches. So now think of it as the fact that like my S3 based, um, uh, access into a global namespace can now happen through caches that can put anywhere.
Um, super excited about that. And, um, TetraTech has long been the soon customer, um, uh, uh, Adrian, we've, we've worked together on lots of other projects including, um, uh, analytics into your system. Um, I know you guys have been a, um, huge supporter of some of the original data propagation analysis that we've done, as well as, um, what's now, um, uh, been announced called Nasuni iq.
But, um, you guys were also there to, um, really help us to think about S3. And so, um, if you wanna talk a little bit about sort of how S3 works within your environment within Tetra Tech or how you're seeing the opportunities for it. Yeah, so, uh, just to, uh, emphasize a couple of points here that you mentioned, John, uh, first of all is, uh, this idea of, um, centralizing, uh, file system, the, the entire, uh, data stores for, for the enterprise, uh, without sacrificing the performance.
So if you have a centralized file system, uh, you need access, quick access, and that is through the caching devices that you mentioned. And second biggest, uh, advantage is, uh, the, the backup and especially the restored. Uh, everybody e every backup system has a big flaw when it comes to disaster recovery.
And, uh, here it was, it's the main advantage because you can restore in minutes or probably hours instead of weeks and, uh, in, in case of a ransomware attack. So those are the two main features that were attractive to us when it started. And after that, we discovered, uh, more and more features that you continuously add to this ecosystem.
Na Sunni is a file services applications. Uh, so it's a big distinction. It's not just a file server file system, it's file services.
So services are added all the time. And you mentioned the SUNY iq, um, side of the basic, uh, anti, uh, um, virus scan and the ransomware protection and so on. This, uh, S3 is the newest edition, and, um, it, it, it, it evolves.
So it's an evolving system. It's exciting, it keeps up with the times. And, um, recently, uh, this S3 that we tested together is, is a, uh, a benefit for it.
It may be a niche, uh, type of, uh, enhancement, but it has a future because more and more application will support natively S3. And this is the, the key part, because uploading data into the cloud from the field, uh, it's a painful, uh, endeavor. Right now.
We have, uh, lots of field engineers going in disaster areas and capturing, uh, huge amounts of data later data, uh, images that they have to be uploaded and processed, um, internally. But right now what they do, they have, uh, they try to use draw box, uh, USB drives. Um, it, it's a multi-step, uh, process that will bring data from the field to the, uh, to in the cloud.
So by, by having S3, uh, protocol available, um, it's streamlined the whole process. Uh, it has a consistent, uh, transfer rate based on our testing is not like windows that goes up and down all the time. And, uh, the SIFs, uh, that has all the limitations.
Uh, this is, uh, it, it's a consistent transfer rate and it's very stable. It's, uh, resilient to, uh, internet disruptions. And, uh, it, it, it's all, it, it has a big future into, um, a, a a range of applications.
We tested with one of two, and it's based on whatever our clients were required from us. Okay. So I'm guessing that, um, part of this, there are a couple things that stood out in what you talked about.
One of them was consistency across environments. Right? Now you're talking about a essentially what a network attached storage like type service in the cloud in, in S3, but also, um, you know, file systems are great for just putting information, but there's a lot of data management practices that go around that, like we talked about, you know, restore points and backup and restore and things like that.
What, what were some of the most important things you needed that S3 didn't have now that you've got uni on top of S3? So for us, um, it, it is the, uh, how you move data from the field to the cloud. Uh, and I'm talking large amount of data, hundreds of gigs, files that are into gigabytes that, uh, you have to process them on the field, put them on connect USB drive mainly, or put them into your Dropbox and go into the office.
And two or three step later on, you, you have data where it has to be. So, S3 is, uh, it works. Um, we, you are testing right now to use VPN less, um, and there are some security issues there, but, uh, nothing that cannot be sold.
Uh, and so it'll be a one touch, uh, data movement from what you have on your laptop in the field to, uh, and the SUNY Edge appliance into the cloud and data will be readily available. They can process it right away. Uh, there are, um, hundreds of, uh, of gigabytes, if not terabytes, of data uploaded daily, that that's the, the biggest problem.
So we have lots of contracts with, um, uh, US agencies that goes into the disaster areas, and there are hundreds of people in the field collecting data for insurance and all this kind of, uh, applications Jump in. John, I, I, you know, I, I'm, I wouldn't be the first person, I'm guess Adrian isn't the first either, has worked with the cloud and said, getting data to the cloud to and from the data, and then synchronize it in cross environments, managing it as a common name space between what's in Amazon AWS and as well as other environments. Um, that, that's, that's a big challenge for data ops groups, if I can use that term, just in general for people in the data business.
Yeah, this is, this is one of the exciting things here is that, um, you know, the, um, the, you know, the promise of the cloud is it's, um, you know, it's capacity, it's, you know, performance. Um, but one of the challenges is trying to work with, you know, a a a company that's been doing, um, you know, kind of amazing engineering work for decades. And a lot of the, you know, current processes don't fit within their, um, uh, within a cloud model.
And, and specifically I was thinking about the, the, the lidar and maybe some of the data flow there, which is, um, it's great to be able to upload NS three, but if you know the way that you're gonna be analyzing that means that I need to mount it as a, um, NFS share or mount it as a, um, a sip share somewhere, and I need to read it because of some other, or some other process, some other application, you know, needs file access. Like, um, that's a really unique thing that Nasuni can do. Um, so rather than having this complicated as, as you were talking about this data ops flow, which is like upload to one location, you know, process in location, and then transform and move it to another location, and then maybe do some processing, then move it to another location.
You know, our, our goal is to simplify that as much as you can. You know, when we say a global namespace, we really mean it, like it's global, everything can access it. And access is, doesn't just mean like, Hey, I have the ability to, um, you know, send a request from some other location.
It's like, I've got the protocol I can access it with. And that's been the one big thing that's been missing in the cloud, which is I wanna be able to write using whatever modern protocol I, I, I, I need. And S3 is kind of the modern object protocol I wanna be able to read as well, and maybe even write as well using these other file protocols.
And, um, Adrian, if I heard what you're saying, like you, you're, you're updo uploading, um, the LIDAR data, it's gonna get processed. Is that process necessarily gonna be in S3 using S3 protocol, or could it also be used, um, using the SIPS protocol for that? Well, there are, uh, specific applications, uh, that, uh, that use them for modeling.
And, uh, so it's mainly sips, uh, when they use them. But the biggest problem is, um, uh, on the operational part, it, there are multiple, uh, locations where data resides. So there are offices sitting on pile of USB drives and we don't know has been uploaded successfully.
Yes or no. S CS is not very reliable on that. It's large amount of data, especially if you go with A VPN.
So, um, just moving that data internally in a reliable fashion, that's the a, a big challenge. So S3, as I said, it, it's a very, um, predictable mm-hmm. Upload, uh, transfer, um, you, you just start it and you can forget about it.
You don't have to watch it all the time or the, the disconnected, or right now it's on zero megabits per secc, uh, kilobits per second, and then so on, and it starts going again. And oh, how long it'll take, I don't know, maybe an hour, maybe a day. So, um, it, it's very, it, it simplifies the whole upload process, the whole, uh, uh, single source of truth for, for later processing.
And we can't talk about data too long without talking about security. And, uh, you know, there are, yeah, you know, some security capabilities that are in the cloud. Different cloud providers have, have their own model.
Of course, we have ours within our environment. Uh, how about how does this help with the, the security aspect of managing that in AWS Um, I could, I could take the first, first crack at that. Sure.
Um, so, um, for us, we've sort of built a lot of our security model in terms of access control around active directory. And so when we have a file system that's built on top of the object storage, we are creating all the metadata structures to be able to represent your active directory controls as well. Um, so when we developed, um, this integration into S3, then kind of confirmed with the idea of like, wait, there's two different types of access controls that are coming into play here.
You've got your ad system, and then you have what is, you know, typically the, the secrets and the access keys that you use for S3 protocol. So, um, we work hard with our customers to figure out how can we best map these two things together. And what we've come up with is a way in which you can create your own secrets and access keys, and you can put them onto an appliance.
And so that appliance will have those secured there. Um, and then you can map those keys to any part of your global file system, any part of the volume. So you can both put it the top level and then give access to the entire entire volume.
Or you can use those keys to be able to map it to lower within the tree, which itself is its own way of being able to, um, map out, uh, security protocols as well. So we kind of think of it almost the way that like, um, NFS users sometimes work with, um, with SIFs users being able to have like admin access or, or, um, super user access across the tree, and then being able to, to map exports to that. Um, but our, our goal here was to make sure that you, you don't have to remigrate or re permission your current global namespace, but we want to be able to have that work in, um, conjunction with the IAM model, the access key model.
And so, um, we feel like we come up with a really nice little nice solution here. It's easy to use, easy to manage, easy to update those, um, uh, those keys. Um, but it doesn't mean that you have to get away from what you're using today, which is, you know, for most, you know, large file infrastructure, it's gonna be, um, active directory.
Yeah. So, um, just to add to that, uh, from our perspective is, uh, side of what Nasuni is doing in terms of security, our security team, it's, it's extremely, uh, diligent into assessing new technology. So anytime we start with a new protocol or a open a, a, a a hole into the firewall, everything goes into a secure area, is monitor for weeks, and, uh, there are reports and security teams give us the blessing at the end of it.
So, um, it's a, uh, defense in depth, uh, and this is what we try to, regardless of what the vendor is saying, we take our own precautions. So, um, this is pretty much what the, how we address security. I'm curious.
Um, so we have to bring up also ai, of course, and people are investing more and more in their, in their, in their products, having AI capabilities, but also in the software that we're developing, uh, including models and machine language algorithms and generative AI as well. But that, that involves pushing a lot of data around, uh, whether it's training, training models, or it's continually feeding new data into models. Um, that data management challenge, transferring that data, you know, models start to drift, they need to be replaced, all those kind of things presents a new set of challenges for a lot of data management teams, I would imagine.
Talk a little bit about how this might help with that. You wanna start out, John? Sure.
Um, so this is the one I'm really excited about because I think there's, um, a lot of things Nasuni does kind of natively today that, um, you know, ai, um, AI engineers of the future will just start to, or just gonna start playing with it. Um, and, um, one big one is the fact that we can version at any level of the global namespace and with a lot of granularity over time. So I like to think of it this way, like if, if, if you think of, um, if you know, um, Adrian's, um, the file systems that, um, Adrian has on us at TetraTech, um, I'm gonna guess I haven't looked at the exact numbers, but I'm gonna guess they have somewhere in the order of a few hundred million restore points.
So if we wanted to, we could actually go back to, um, let's say a year and a half ago, we could pick a random date a year and a half ago, and we would say, what if we trained a model off of the dataset that existed on that day? We could do that with Nasuni. And to do that, like it really requires you to figure out, well, which part of the tree do I want to be able to train it off of?
Maybe it's the projects folder. Maybe it's a specific subset of projects, folders, maybe it's a combination of different projects, folders. And then we would tell the system, okay, let's restore in a read only way, just say an appliance to that point in time.
Well, if you started to train on that day, just that point in time, and then you move forward and you trained a different day, what we've basically allowed is for you to take a training set instead of starting on day one. You can go back in time and start training your data from as long as you've been on Nasuni. And I think the power of AI, as we've seen it today, is the fact that I can keep retraining these models, but almost everyone starts, uh, from like, you know, T zero as like the day I start my training model.
You don't have to do that with na Sunni, start with whenever you start create your Nasuni volume. So now TetraTech is available to them, you know, literally like, you know, um, a thousand times more actual training sets that they can use to train their model just by the fact that we have this incredibly granular version file system. So that's the one I'm super excited about.
Um, the second thing is the fact that the S3 protocol is kind of a modern protocol. It's the one that works within a lot of these, um, kind of more AI based workflows. If you have a data scientist that is, um, you know, um, is, you know, working off of their Jupyter notebook and wants to test something very quickly, um, boy, it's so much easier to say, okay, well just point it to this S3 endpoint now than, you know, point it to another S3 endpoint.
Some of them do use files and you might wanna mount a, a directory, but, um, we just give you a lot of flexibility for how your AI engineers, your, your, um, ML engineers wanna work today by just giving them a protocol that, um, that works so easily with their tools. So I'd say those are, those are two of the things. Yeah.
So, uh, um, for us at the Tera Tech right now, the, the main emphasis is to provide more services to our clients. So, uh, traditionally we just gather data, process it, and submit it to the clients. They locate to it, they use it for a while, and that's it.
Um, using an AI will allow us to provide more services, give them, uh, the ability to search through by years and years of collaboration and, um, e extract more value out of the existing data. So it, it's definitely very an exciting field and, uh, we're just scratching the surface of the surface at this point. So it's a long way to go, but data is there.
And as you mentioned, there are so many restore points that we can go really granular and, uh, be very specific. And I think many organizations are, are starting to learn some new challenges with generative AI and the training and, and, uh, you know, prompt engineering. And so that, so there's a lot of data that you need to both develop and test those environments before it ever makes it to production as well.
1 point a, but what was that, right? Just to give a kind of ridiculously but probably common example. Um, are any other things on the announcement that you wanted to make sure we cover?
Uh, just, um, uh, a couple of the, um, the points that I think kind of were made here before, which is, again, it's all part of the existing na Sunni system of existing na Sunni volumes. You can apply that to the, um, S3 protocol to that. Um, one other little thing to touch on, um, because we're a version file system, because we're based off of, uh, um, really the appliances are using XFS underneath, but we're creating our own uni FS file system in the background.
We have our own way of storing metadata. And what that means is that when we implement the S3 protocol, we now allow you to add more metadata than you would just using your standard S3 service. Hmm.
And, um, we're, we've seen customers get excited about that already. Um, I think more and more as we're in this AI space more and more where metadata becomes, um, such a locus of innovation, um, just having the ability to have more than say like, you know, 12 pairs of 12 key value pairs, or more than, you know, 4K of, um, metadata. It's, we, we've, we've tested well, well beyond that and, um, the system, it's, that supports very large metadata structures.
So we're excited because now you can, um, think about your S3 target, not just as data, but think of it as being metadata rich as well. Fascinating. Any other points you wanted to make Adrian?
Uh, no, I think we touched on pretty much on anything, uh, that was pertinent for, for this. And, uh, I, I'm looking forward to, uh, I, I'm pretty sure S3 has a future because it's something native to the cloud. So, uh, we're excited to explore more and more applica, hopefully more and more vendors will have applications that supports S3 natively.
Um, so, uh, this is something that, um, we're looking forward to as it is right now. They, you, you need a third party client. Um, scalability is, I mean, if you want to go to thousands of users, uh, you have to manage something extra, but I'm pretty sure that the future is there for S3.
So, uh, looking forward. Well, fantastic. Congratulations on the announcement.
Ready to, uh, have this out in market. Where can folks find out a little bit more about this? John?
com. com/ S3 edge, in particular, S3 Edge E dge. All right, excellent.
Well, thank you, gentlemen. It was great talking with you. It's always, uh, it's fascinating.
It's kind of another way the cloud kind of grows up, right? It's, it, it innovates in its own way, and this is also makes it a little easier for all of us to use all that great storage we have up there in meaningful ways as well. AI being a big important one.
So thank you. Thank you, John. Thank you, Adrian.
Thank you. Thanks to talking again soon. Take care.
Thanks. Bye. Nel.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Then we have a, a view with ARD today. Mike Ard has Michael Stone breaker, chief scientist for DBOS, and he's gonna explain why the time has come to replace Linux and Kubernetes with an operating system based on a database that is much simpler to Mar to manage. I know Michael, he's a great guy.
I don't know if I agree with him on this one, but we'll see. Here's the view of his art. This is Textron tv.
Hey guys, thanks for the throw. We're here with Michael Stoneberg, who is now leading an outfit called deboss, and we're talking about the convergence of databases and operating systems and the cloud and functions and all kinds of fun stuff, but they just raised some additional funding, and we're gonna dive into what all that means. Michael, welcome to show.
Thank you, Michael. Glad to be here. So what is it you guys are trying to do?
Because, well, we've had databases and operating systems, you know, tangentially related all these years, but what's changing and how come we need to rethink all this stuff? Okay, uh, the, well, this, this, uh, deboss project started in 2020 as the research project at MIT and Stanford, and we were motivated by two, two points. The first was, uh, Linux is very elderly.
Uh, I, and I first used UNIX on a PD P 1140, uh, one processor. Uh, this was in 1974, uh, 48 K, not m or G of main memory, and 20 gigabyte, 20 megabytes of disc. Uh, one of the environments in which, uh, DeVos runs is the MIT Supercloud, which is 32,000 processors, several terabytes of main memory and many terabytes of secondary storage.
So that means the resources that the operating system has to manage has gone up by about six orders of magnitude, uh, you know, in the last 40 ish years. So, uh, without me saying another word that makes managing operating system state a database problem. So, uh, and Linux, of course, knows nothing about databases and Linux, uh, is elderly, is having a hard time making forward progress fast.
So, for example, there's no multi-node version of Linux. You've gotta run something like Kubernetes. You get a fairly complicated stack.
So, uh, basically, uh, it's time to send Linux to the home for retired software. Uh, and so that's what we are attempting to do. That's number one.
Uh, and so we have a commercial version of a replacement for Linux. And to no one's surprise if this managing state is a big problem. You wanna run a database in the kernel, and you wanna basically, uh, run everything on top of a database.
So the way to think about deboss is you're familiar with running an operating system on top, uh, underneath a database system. That's the way everything runs these days. We do exactly the opposite, which we run the operating system on top of, uh, the database.
And so, operating system services are written in sql, and this puppy is fast enough, and it has much, it has great properties. Uh, so for example, uh, if the database is the only thing running, uh, then one of the things that the database does is logs events. That's what databases do.
So we capture all events and we log them into transactionally, into a data warehouse. So if you'd like to back up the operating system 10 minutes, uh, just go ahead and do it. So we, we support time travel in the operating system, and if the, uh, and if the database is fast enough to manage operating system state, it's fast enough to run your application state.
So you should put your application state in the same database, and then you time travel everything. So if there's a ransomware attack nine minutes ago, you just back up everything, 10 minutes, single step around the, the intrusion and keep going. So it has wonderful security properties.
So that's, that's number one. We, you know, uh, deboss is an attempt to displace Linux and Kubernetes, uh, and a bunch of other, you know, like if you're running a transactional file system, well that comes built in 'cause databases are transactional. So it basically simplifies the operating system stack a whole bunch.
So, and that's just plain goodness. mm-Hmm, uh, and it's much more secure. But then the other thing that we do is, uh, in terms of how do you write applications for this operating system?
Well, we could implement p uh, which is sort of yesterday's standard. And in the modern, uh, cloud oriented software service oriented world, hardly anybody cares about s So we have a new programming environment, uh, which is, uh, transactional. It's, it's basically a TypeScript environment in which everything goes into the database, uh, and it's software as a service.
So you structure your application as a collection of modules that are connected in the graph. Each module is transactional. Each module is durable.
Uh, so this creates a very nice programming environment, uh, that's database oriented, transaction oriented, and, uh, and in my opinion, a a great, a great way to worry about, um, not doing your applications. So we have two things. We have a new operating system, and we have a new programming environment, uh, that both of which we're very proud of.
Much to unpack there. Was it not possible to think about just upgrading or modernizing Linux in a way that would add a database capability to it? Or do we need to replace the entire stack?
Well, in my, in my opinion, uh, in my opinion, Linux ought to do that. Uh, but that still leaves it, uh, with mountains of code that are, that's a leaky boat, security wise. Uh, and, uh, that would, that would allow you to, since, since if you upgrade Linux with a database, then, uh, the database is multi-node, uh, and you've now got a bunch of engineering to make Linux multi-node.
So it's, it's considerable amount of work. But in my opinion, uh, my opinion, all future operating systems should have a database at the bottom. And there's a, a good reason for that.
I can give you two quick vignettes. Uh, the first one, which was occurred in 2020, which was when we were just about to start the boss and I listened to a talk by Mattes Har, who was the founder of Databricks, of course. And Matta said, uh, on a routine day, Databricks, which manages spark instances in the cloud, uh, Databricks manages a million, uh, spark subtask.
And he said, scheduling a million things using conventional technology, just, you know, as, as a non-starter. So, uh, Databricks and a bunch of other big, uh, cloud properties, uh, manage, uh, state and manage scheduling out of the database. So Matay, uh, Databricks is already using some of our ideas.
And of course, uh, Matay started whining about, uh, Postgres performance, which is what they were using for scheduling. So I said, we can do better than that. So first, first, uh, thing is that big properties are realizing that you can't do operating system scheduling.
You need to do scheduling, scalable scheduling. Uh, the second thing is, you know, Uber, uh, the guys that, uh, drive you around in the city, uh, they have a programming environment where, uh, they have a collection of schemas. And you, the way you share data is you add columns to this, to this schema.
So everything, all sharing goes through the database, which is exactly what we're advocating. So forward, forward thinking, companies are already, you know, using some of our ideas. We just, uh, make it all simple and easy.
The future, will I also need a, a separate database still from my application? Or is that something I'm gonna invoke directly from the new operating system? Uh, the way deboss works is that we store operating system data in a thing called Foundation db, which is open source.
Uh, our investors said, you've gotta have an open source offering. And so we do. And Foundation DB is not a relational database system, so we thought users would walk at putting their data in it.
So we allow you to put your data in any Postgres compliant DBMS, pick your favorite poison. Uh, and from my point of view, all of the big, uh, cloud properties are standardizing on, uh, Postgres wire compatible DBMS. So run, run, uh, cockroach, run situs, run Ugo byte, run, RDS run, Postgres, run whatever you want.
Uh, and it's in the kernel. So the answer is your favorite database system should go in the kernel. Uh, and, uh, from our point of view, we're happy to be user database agnostic.
Uh, and if, if, uh, if it comes to, if it comes to it, we will write a database system at some point if that's turns out to be a, a good business decision. Architecturally, have we kind of painted ourselves into a corner because we have Linux and Kubernetes and all these things and, and stitching them together, and, um, managing them adds a level of complexity. And we invest in observability and monitoring tools.
And the whole stack seems to have gotten fairly weighty over the years. So, you know, at what point do we kind of, um, have to do something? 'cause the current pressure of the stack is just too much.
Uh, that's another reason to move to Debo. So all that stuff goes away. So if I'm managing the environment and all that information is in the database, then am I just launching a, uh, a SQL query to surface that?
Or, because today I have to kind of use various querying tools, and a lot of people don't know exactly how to make that, uh, work because, well, they're all written in these kind of proprietary formats. Exactly. So you could give my pitch, excuse me.
So all operating system state is in the database. So if you wanna know anything about what's happening, you just run a SQL query. So if you wanna know how many users are chewing up space, only counting, uh, uh, files that are bigger than a hundred gigabytes, that's just a SQL query.
'cause, uh, remember the way debos works is we have, we have a message system. It's written in sql. So there is a message table with a sender, a receiver, and a payload.
And to send a message, you do a SQL insert into this table. Uh, and that table is partition. So it ends up, uh, the, the bites in your message end up at the home node of the receiver who reads a message by doing a SQL query.
So that's all you have to do. And you can, since the message system is a table, anybody can query it in sql. Uh, and if you, you wanna say how, uh, if you have a suspected bad actor and you wanna say, tell me everybody who's sent the bad actor a message or received a message from the bad actor in the last two hours just to sequel query, whereas today, uh, it's essentially impossible to find that information.
You talked about the cybersecurity implications of all of this. Um, do you think that they'll be involved in this decision making process or this transition, or are they gonna exert a lot of influence on that? Or is it more like a, a, a downstream benefit that they'll appreciate one day, but today they're not that involved?
Well, here's my point of view, which is everyone is moving everything they can to the cloud as quickly as they can. And so one way to deal with the cloud is to do a lift and shift. Uh, and if you do that, then the successor in your job will inherit all the problems you currently have.
So, in my opinion, you have a once in a generation opportunity to make your software system better. Uh, and so adventuresome enterprises, I think, are willing to refactor, rewrite, uh, put green, uh, do green fields in a better way. So our point of view is we are appealing, uh, primarily to say deboss is only, uh, runs on the cloud.
Uh, we will offer an on-prem solution if we have to at some point, but the cloud is where things are going. Uh, and on the cloud, you are highly encouraged to run software as a service. Uh, all you have to do is look at Amazon pricing, uh, to figure that out.
And so if you're gonna move to a software ser as a service environment on the cloud, uh, it's just natural to run our stuff, uh, rather, and if you're gonna refactor what you're currently running, uh, you might as well refactor it into us rather than into something else. Mm-Hmm. So, uh, we, we are, we are planning on, uh, marketing to adventure some enterprises as they move to the cloud.
Also, the three letter agencies, uh, love our security story. Mm-Hmm. Uh, and also, uh, financial services folks, uh, love us for a different reason, uh, which is, are you familiar with the term Once and only once?
Um, it's been a while, but yeah, I seem to remember hearing that a while back. So just for example, if, if I want, if I want to, uh, give you a hundred dollars, uh, your, your finances are presumably in a different system than mine. Uh, and this application was motivated by a large, uh, northeast regional bank who we talked to at, at some length, and are plan, they are planning to be an early, uh, deboss user.
So the way they, the way they do it is they, they debit my account, then they send a message to your system, they increment your system, they get a return message back to my system, and then you want to commit the transaction. And only then, uh, and of course your system and my system, uh, in the banking world are unlikely to implement Xa meaning they're unlikely to implement distributed transactions, which is what you need to do once and only once, which is this, this whole, this whole saga either, you know, uh, runs to completion or it looks like it never happened. So because we run the message system, uh, we can do once and only once, uh, banking transactions, and that's very attractive to this particular regional bank.
Uh, they figure that, uh, somewhere between a third and a half of their application code is making sure that this stuff works. Uh, and so distributed transactions are not for the faint of heart. And if you do them an application code, they're brittle.
There's a lot of code they tend to screw up. So this regional bank would love to get rid of all that. Uh, and so they, they are incented to move to a new environment by the ability to, to do once and only once, uh, in a much cleaner way.
Hmm. I'm suddenly having memories of misadventures with two-phase commits and all that fun stuff. Right?
Exactly. All right. So today, everywhere you turn around, there's these massive investments in ai.
Um, and a lot of that is in the realm of AI ops. Um, are we investing in AI as it relates to IT operations to compensate for the complexity? But maybe we should be going the other way and just reducing the complexity, Uh, to the ex.
Uh, I think, uh, you said it perfectly about 10 minutes ago, which is the current operating environment that people are trying to manage is ridiculously complicated. Uh, you need a Linux administrator, you need a Kubernetes administrator. You've gotta make sure that, uh, your Linux settings and your Kubernetes system, uh, settings don't conflict.
Uh, you may be running a transactional file system, you may be running a separate high availability system. Uh, you're probably investing in two or three, uh, security oriented monitoring products. Getting all that stuff to work correctly is daunting.
So we promise a much simpler life that will make, uh, it'll make operations a great deal simpler. Uh, and, uh, from my point of view, that's totally separate from chat, GPT and other large language models, which are basically decision support like things, uh, and we are not particularly focused on decision support since they are, they are often don't care about transactions, don't care about high availability, don't care about recovery and so forth. All right, folks, you heard it here.
The principle is still the same, right? Keep it simple, stupid, and you'll have a happier life. Hey, Michael, thanks for being on the show.
Oh, thanks for your time, Michael. All right. And back to you guys in the, All right, we got a Chock-full lineup today on Tech Trunk tv.
I hope you enjoyed it all. Uh, we'll be back tomorrow with more, but until then, this is Alan Sheel for Tech Trunk tv. Be safe, be strong, be tech strong.
Happy Thursday, everyone. We've got a lot of AI stuff to go over with you, as well as some news on the security bloggers network, security creators network, A RSA, all of this, some more you are watching Tech Drunk Gang. Hi, everyone, happy Thursday.
It's Alan Hummel here, uh, CEO and, uh, Techron. And you're watching The Techron Gang, as I mentioned. Let me tell you what gang members we've got on for today.
First of all, as usual, joining us from, uh, high up in the Rocky Mountains. It's our CTO and principal research analyst, Mitchell. Ashley.
Hey, Mitch. Welcome. Happy Thursday.
What a great day. Happy Thursday to you joining a, a Roving gang member joining us from the Raleigh Durham Triangle area. I think if he's home.
Anyway, our AI expert, mark Kel. Hey, mark, welcome. Thanks Alan.
And I am home for once. Good, good for you. I'm glad you made it home.
Um, and then joining me here in our Boca Raton Headquarters Studios, our Echo Insights editor and lady about town, Bonnie Schneider. Hi, Bonnie. Hi, Ellen.
Great to be here. Thanks to have you here. So guys, let's just jump into stuff today.
ai site, and it's, it's basically a welcome or acknowledging, I think, I don't know if a welcome's the right word, acknowledging, uh, that we are entering the generative AI election era as if our elections didn't have enough aggravation before AI with meddling and social media and fake news and everything else. Now we've got AI to crank it up. Mark, you're the AI guy.
What do you, what do you think It's gonna be a wild ride? Um, you know, in the last three months, it seems like every day there's some kind of new AI model that does text to video. They're getting better.
Um, they're, you know, we are gonna have to have a real critical eye for this election and for the news in general going forward. It's just the barrier to creating realistic deep fakes and videos in Now, you know, voice cloning has gotten really, really good too. I think it's a matter of security for everyone from phishing schemes to, you know, news misinformation based on generative AI being, you know, so good so fast.
Yeah. Yeah. I see.
I already see the AI out there in terms of bots, like bots, anytime, um, someone posts something political on, on social media, it'll be followed by lots of, um, I think bot accounts, because if you look, they have very few followers and they're influencing, or they're disrupting. They're, they're designed to make people argue with each other on social media. So we're seeing that now, and I think be now, and I think because it is an election year, this is only gonna escalate.
And as, as Mark mentioned, those DeepFakes, I mean, they're pretty convincing. Now, some of them, especially if you're not paying attention, you think it is, um, a candidate or someone that's running. So messaging and AI's influence on messaging is gonna be something to watch.
Absolutely. You know, putting the election stuff aside for a second, I still read another article today about a, a pretty widespread problem we're having in high schools and colleges. And that is with deep fakes of like fake nude shots of, of especially of women, girls, right?
That, uh, using ai, you know, it's, it's the cool thing to kind of make, make AI images fake images of, you know, women's faces or girls in school's faces on, on kind of pornographic bodies or nude bodies doing pornographic things, you know? And, and that's not new. Of course, people have been Photoshopping and playing that game, but AI, of course, takes that to a whole nother level.
The, to me, that, and what we're talking about with the election stuff really points to the same issue we've been having now since kind of the rise of social media. And that is that as a body politic, as a civilization, we can't discern truth from fiction and with AI and bots and, and, and the bots really are there to gain the system, right? Because the way these algorithms work, the more, excuse me, the more likes or comments a particular post gets, the higher up its visibility, the more it trends.
And our system is based on that. The whole social media kind of algorithm is based on that. And, and, you know, people are gaming it.
I, I mean, I was on a podcast a couple of weeks ago for not here on Techstrong. Someone had invited me on their podcast, and when it was published, they asked me to put it on LinkedIn because they have a cadre of followers who will like it and share it and push it to help gain the LinkedIn algorithm. And I get it.
You want, you want to get your stuff out there, but this is, this is the world we live in, and now you add AI to the mix, that's like turbocharging that kind of activity. And I, yeah, I think it's taken to another level, right? Yeah.
I, I, I can't imagine as, as Mark said right off the bat, it's trouble, it's trouble. How are we, how how's the average person supposed to get their information and ascertain truth from fiction here? You know, the head headline grabbing stuff, you know, we talked about the deep fakes and people putting images, people's faces on Images, et cetera.
Those are the things that are, are easy to at least talk about maybe getting more challenging to spot. What I think is, is interesting is both everyone who's doing creative writing of some type is, is using generative AI as a tool in that process. I mean, 'cause they wanna learn it usually, but also it's an aid in doing that.
I, I'm interested in, in how you could take generative AI and both craft multiple prompts for a particular topic or article, but then, and then create your own echo chamber where you could be reposting and having generative AI create, create 25 different ways of reposting the following article. And you can do that through an API, and you can do that through posting on multiple accounts. So we could see a real escalation of the number of kind of fake posts that are happening and some real manipulation taking that, you know, gaming the, the system up.
I think another level, I, I absolutely. I, you know, so what, what's the answer here though? Where, where's the light at the end of the tunnel tunnel?
Or are we just all, Well, there's definitely talk, obviously, of, of some regulation, but you're right, it is already a problem. And, um, it isn't easy to tell what's true and what isn't. I think that the, the, because going back to the fact that it's an election year, I think that the, those, those fake accounts and, um, the superficial ones are gonna be, um, watched even further.
And who knows? I mean, if it gets to the point where it gets, let's say, where it really causes a, a, a widespread misinformation event that that'll just put more spotlight on it. But I, I think, I think it, like, it's gonna just go upwards in terms of attention and an escalation.
And, um, the bots that I mentioned straight into November, I, I think it's already caused a widespread, I think if you go back to the 2016 presidential election, that was Trump and Clinton, Hillary Clinton, you know, the, the Russian meddling using, and that was before AI per se, but the Russian meddling, using fake accounts and, and trying to gain the algorithms that we've seen absolutely had a, a, a impact in that election. And I think also, what I forget the name now, of the British firm that was hired by one of the candidates, um, Cambridge Analytics. Cambridge Analytics, that's it, mark.
Um, and that was before they had generative AI as a tool. Imagine, you know, a Cambridge analytics type of operation now, a generate armed with gen AI type of functionality. I, I don't know, do you put a total ban on, on political ads and, and commentary?
How, how are people supposed to get their information and how, how sophisticated did they have to be to, you know, truth from fiction here? I I, I, I'm at a loss. I, you know, I hate to be pessimistic, but I'm not, I, I don't know what to say.
Well, I think There is a legislation, I think introduced by Holly and Koons, if I remember right. Uh, protect elections from AI for deceptive ai. I don't know if that'll go anywhere, but even if it does, you know, that's never stopped.
The, the ransomware dudes and everybody else doing Things, they shouldn't be doing guns only, gun only outlaws have guns. Yeah, exactly. But I think that particular AI law was more to stop sort of robocall with fake voices with, you Know, this was deep fakes.
Yeah. Yeah. I think it was prompted by that robocall that Mark, you were gonna say something?
Yeah, I think actually you started out, I think you have part of the answer already. And I think that when you, like you're talking about the security bloggers network and the security creators is, I think that we, in the short term, it's gonna be a mess. In the longer term, I think we start to have more of a relationship with individual news reporters.
So I feel like, you know, I see the Creator newsletter economy, some of it's game, all of it's always gonna be gamed. But I look at like Matt, who was, you know, a respected journalist and then did the Twitter files, and now he has racket news. And I feel like in the long term, the transparency is hard for a big corporation and for a smaller person who's staking their career on their integrity, you know, I think more of these citizen journalists are what they called them 20 some years ago, and now we call them creators, but they're sensationalists.
But I also think there's a lot of folks out there that are, you know, gonna make their bones on being good journalists and citizen journalists instead of, you know, part of the big media conglomerates that, you know, 80% of our news is paid for right now by big pharma. I mean, that's, that's part of the, the, the whole problem is that the, the model is in a meritocracy. You know, William Morris turning over in his grave right now going, Well, it's definitely a rise of independent journalists for sure.
Um, and that keeps on growing, um, as well. But what's interesting with the ai, another way the AI influences us, is it also kind of keeps us within our own ecosystem. Like, it, it knows we like tribal, right?
Which isn't good because it's, it's, it's better if people are with opposing ideas, get to debate them rather than just be with somebody With you. But I, I think what we have found is that people want to get their own views amplified. Yeah.
So they tend to stay in a tribe where their own world views are amplified and That, and validated, right? And yeah. And other people believe like I do.
Yep. And I, I, and you know, I've read articles where this is translating like some of the first time in the US anyway, anyway, to people picking where they wanna live, right? They, they wanna live in a red state or a blue state, but not just at the state level.
They want to be in a neighborhood. How did that neighborhood vote? Wow.
What's the political, I have no idea what my neighborhood vote. Yeah. You know, and, and it been a bunch of articles.
500,000 people have moved outta Florida in the last, I think two years. Many more have moved in, but for the people moving out, one of the big things in addition to cost of living insurance was the, the, the political hate, if you will, uh, a among the populace here. And it, it, again, you've got, if you've got actors who want to play that out and heighten the, the, you know, the, the divide and, and try to sway elections and stuff, this is a great tool for them.
And I don't know, I don't know how you could stop them from using it. So anyway, make good choices. Dig into the information you're looking at.
You know, democracy depends on free and fair elections. And, um, I think it's all of our duty to, to, you know, make sure we're, we're not being fooled. And, and by the way, it's not just a US issue.
You're seeing this in every, in every democracy and in, and, and non democracies worldwide. So anyway, let's hope we figure out a solution to this sooner than later. We're gonna take a break on Textron gang.
We'll be right back. com is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more.
com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more. com to learn more. com, where the world meets DevOps.
Hey, everyone, we're back here on Textron Gang. Our next subject, again is AI related, and, but it, we're getting away from the politics and the doom and gloom. It's, can organizations afford LLM?
So maybe it is doom and gloom. Um, you know, we've spent a lot of time recently here on the gang and on our tech strong sites talking about, you know, will as, as this whole AI thing unfolds, we're learning not all LLMs are created equal. And some LLMs and some s SLMs will be better for certain jobs.
And it's about using the right tool for the job. And, and in this case, that tool is an LLM, but you know, we, we talk like LLMs are something you could go in the candy store and buying a baseball card pack with a pack with a little piece of bubble gum. No, there's more to an LLM than that, I think.
Um, and can the organizations who are gonna rely on these LLMs actually afford to sort of do the customization work that's really going to, you know, give them the ultimate value there? So Mark, what do you think? Yeah, I think you have to break it down into a couple different categories.
So the, the thing that is the most resource intensive with LLMs is training it on your data and training is, is taking an algorithm and using machine learning to populate that LLM. Those are the things that like OpenAI is doing that generates those sensational power usage stats. Then when you and I use Google Gemini or chat CPT, it's doing something called inference.
And the inference is less CPQ intensive. So what isn't practical for a lot of organizations is the training. So that's when you download what's called a foundational model.
Like, uh, um, meta Has Llama or Mistral is another, um, popular vendor of these sort of open access or open source models. And then those things don't take as much, but it's like everything in technology, the more that we, it's available, the more we consume. It's that way, you know, the amount that we drove our cars versus in the twenties has gone up substantially.
The amount that we use our desktop computers and our smartphones can, can use to RISE and the MA amount that we use ai. So, um, I think the, the takeaway is this is LLMs are easily accessible. The compute that underlies them is what's expensive.
So that's the, the Nvidia GPUs, that's, um, Brock with a, uh, Q is another vendor there. There's a ton, ton of up and comers there that are all going to, um, have this problem to solve, is how can they reduce the amount of power they consume while they're producing more and more inference, and in some cases, training Fair Farney. Well, Uh, we were talking about cast ai, and they have a new product that's optimizing this, um, which is interesting because when I was looking into it, um, the, the, the, the pitch is, well, it's more cost effective, but there's also a sustainability angle.
Because if they're optimizing cost and they're using, um, less energy, they're also freeing up the, um, ability to focus on other products and other things at the same time. So it's, it's ai um, point is that it's cost effective, but I was thinking that, um, if if they're optimizing it, then it's gonna be using less energy, and that's, you know, beneficial to sustainability. But that's just maybe in the smaller picture of that product.
Well, part of it is they, what CAST has done, to your point, is they've added the AI aspect to running on, uh, Kubernetes, which they already monitor to Kubernetes and cloud environments. And I guess this is gonna be offered as part of Google, uh, GCP initially, but it's, it's kind of the larger finops of managing costs. Um, uh, I'm curious, I I I'm doubtful that they're gonna recommend different, uh, LLMs for the one that you're using.
Maybe they will, but that seems to be such a fast changing landscape. And I wonder too, you know, I'm thinking we want to be flexible and don't get too tied into a single LLM, but Mark, once you've trained, if you've trained data into an LLM, you're not gonna be punting and going somewhere else, aren't you? No.
I mean, you, you may have a foundational model that you actually access data through a Vector database, and that makes it sort of portable, but they're not so much portable. I think it's more like a dashboard approach. But if we look, and I was an early cloud guy.
I mean, Apache Cloud Stack was one of the early and open stack cloud providers, and we've talked about, you know, this arbitrage of cloud forever and ever. And what happens is that people do not, you know, dynamically switch workloads. It just, they just keep an eye on the cost.
There's, there's been tons, you know, NetApp has SPOT IBM has cost optimization tools. There's a lot of these tools, but they're not, no one has sort of cracked that code in cloud, and there's not a whole lot of difference in AI other than it's a different workload you're monitoring. So, and then you, you, you really have to take this holistically as, you know, we talked a little earlier in the show about, you know, power consumption versus cost now, you know, and then the amount of work, how do we measure work if it's inference versus training?
So I think it's, it's a pretty complex thing to crack. Um, it's good to know what your costs are, but at the end of the day, the, the sort of core services just like storage on Amazon and Google and compute, that's a race to zero. And I mean, it's a commoditization play in the long term, hopefully given once we get past the GP shortage.
Yeah. Um, you know, also, I would be remiss not to say that a Google Cloud next is going on right now out in Vegas. Mike Ard, our chief content officer, is not on the gang today.
I was hoping to have a live report from him at Google, Google Cloud, but I don't know if we're gonna pull that off. But they touted a bunch of, uh, new AI advances too, around this. Do you see us moving to a place where different LL different LLMs are available in a marketplace, if you will.
Right? And, and you could kind of sass your LLM, if you will, right? You don't have to buy it, you just rent it.
And maybe it has, you know, it's trained a certain way, or it's trained for healthcare, it's trained for finance, it's trained for pharma, or what have you. And this way the, the amount of investment in time and resources that an organization would need to put in to have, you know, a specialized LLM might be more affordable, might be easier, you know, more fungible. Yeah.
That cast announcement came from, um, Las Vegas, uh, yesterday. Yep. Sorry, Mitch, go ahead.
Gonna talk. Go ahead, Mike. Yeah, so the thing that they are doing right now, there's two things, is what we're seeing is these models that are called mixture of experts, which nails what Alan is saying.
So it has this routing layer that says what expert is the best for this? So if Bonnie has a climate change question, or Alan has a question about, you know, style or whatever, it's gonna route it the best expert. But in the long term, what I think we're gonna see is this gateway.
And so, uh, Kong, which is a big, uh, gateway provider for regular data, has just released an open source gateway that's gonna say exactly what you did is depending on your use case. So we may have what I call our general LLM, the Google of LLMs, maybe it's chat GBT, and then we're gonna have, you know, med GPT, and we're gonna have lawyer GPT, and we're gonna have those things. And you're gonna have these gateways, I believe, that'll route your questions to some, you know, maybe not a marketplace, but pre-approved like models.
So you may have an internal model for the tech strong gang that has your internal dialogue versus us asking general election questions of Chachi, BT or Gemini, or someone like that. Fair enough. I mean, we, we will have to see how that, you know, makes its way to market.
Uh, you know, again, I I, we're so early in the gen AI story, so, you know, can organizations of afford LLMs talk to me in two, three years? And I, I'll have a much better handle on that and, and, and steer, you know, opinion. I, I think we're in such a rapidly evolving, changing cycle right now that what's, you know, prohibitively expensive today, is affordable tomorrow.
And, and what's affordable today is, is is quite likely commodity tomorrow. Right? And, and, you know, and what's the, what's open source gonna have, uh, a play a role in here, in, in keeping, you know, that whole ecosystem open and, and somewhat affordable, hopefully.
Um, you know, Alan, I feel like we're living in a, a giant experiment, which is, you know, every piece of software that I use has some kind of an AI element to it. Most of 'em want to charge you nine bucks a month or whatever it is, right? I can't afford to do it on all of them, but most of them, you know, since it's in software, they can tell if you copy it or you copy button or you do a thumbs up.
So it's kind of got this built in training, almost like we would train a through some ML algorithms to start to learn what are useful uses of Gen ai. Just sticking it on your email client doesn't make it a better email client, right? Sticking in front of a database of documents, well, might be helpful, might not, but we're, we're kind learn, as you mentioned, we're early, but we're also learning in real time what's useful.
And people that get really smart about how their technology is being used, I think are gonna have a leg up. Agreed. I, I don't, you know, I, I absolutely agree with you there, Mitchell.
It's, I gotta tell you though, first I thought you were gonna tell me that we're all living in some AI matrix or something, right? Red pill. You, You were, you were thinking I was going matrix, I was going red pill, blue pill already, you know?
But, um, We are batteries, but that's another topic. Mm-Hmm. Just, Just a little data point to that, to your point, Alan, of like, I remember getting on the internet in the late eighties, and if you had a T three at your office that was super fast, that was 44 megabits per second.
Today, 25 years later, I have a gigabit, which is to my home fiber, to the home that's consumer. Uh, T one back or T three, back in those days, cost tens upon tens of thousands of No, T three was about 40, 40 to $50,000. Yeah.
45 grand. Yeah, it's five. It was five grand a month, five to 10, depending on where you are.
Yeah. Yeah. Today I have for a hundred dollars a month or less, I have, you know, 20 times the bandwidth that, or, you know, less than, you know, like 1% of the cost.
So that's, I mean, I think, You know how technology works, right? So now all of the apps you use require 10 times the bandwidth to really use them well. Yeah.
And, you know, you wanna watch that video in HDR, just plain old fashioned hd. Um, so, you know, there, there, there's that, there's that, and it, and it is, I, I see it in my house as well. Um, it, it does kind of freak me out.
com era company called Inter Reliant. And we were buying, uh, T three and T one lines from WorldCom, if you remember, back in WorldCom, and then this company to us, and said, oh, we, we could arbitrage your, your, uh, bandwidth cost, and we can be a better bandwidth provide provider for you. So I went down with the CEO of my company and our VP of, uh, our CTO to Houston and this big building with a biggie in front of it, and, um, went all the way up to the top floor.
And, you know, I remember they gave us a whole pitch on, on bandwidth mitigation and arbitrage. And I asked my CEO, 'cause I, I was younger then, I a little more naive. I said, her, is this real?
What do you think? He said, these guys are either the biggest geniuses in the world, or they're crooks. Well, it was Enron and they were crooks.
Um, so, you know, who knows what, what, what the future holds when it comes to these things. But it, it, it's certainly is there. Anyway, we're gonna take a break here on, uh, Textron Gang.
We're back with our third block. It's, we're gonna move off AI a little bit to security, so stay tuned. All right, we're back here on Textron Gang.
Our last block today is something that's very personal to me. Um, we recently put out a press release and a blog I'm writing should be out by the time. This is, uh, on Textron TV that we have renamed the Security Bloggers Network.
The Security Creators Network. And this year at the RSA conference, instead of doing our usual security bloggers meetup, we're actually gonna do the Security Creators meetup. What does that all mean?
Well, let me give you a little history in the genesis of the security bloggers network and, and Mitch Mitchell. Ashley, by the way, was right at my side when all of this happened so he could verify. What I'm telling you is, is the truth.
Um, I was, Mitchell and I had helped co-found a company called Still Secure Back in the early two thousands, 2000, 2001. And the, and the, uh, uh, VC behind that was our good friend Brad felt Brad was investing in many companies back then as the whole Web two oh thing was really starting to kick in. And, uh, Brad Invi introduced me to a fellow named Dick Costlow.
Dick at the time was the founder of a company called Feed Burner out of Chicago. Dick went on to become the CEO of Twitter, but at the time, he was the founder, CEO of Feed Burner. And also at that time, the world of the RSS kinda syndication, really simple syndication was like the tower of Ba Babel.
There were multiple standards of RSS, much like SBOs and stuff like that today. And just because you were able to render one version of RSS didn't mean you could read other RSS versions. What FeedBurner did was standardize the RSS feeds.
So no matter whether you were using RSS one r, SS two, Adam, or any of the others, if you used FeedBurner, your, your blog or whatever you were using to syndicate displayed correctly, it was great. What a great concept, what great technology, but how did you make money from it? And so, Dick Costal Law had this great idea of if he could bundle like-minded blogs on, you know, similar topics, he could then sell advertising into that syndicated feed.
Excuse me. And so Dick asked, well, Brad Feld put together the, the VC Bloggers Network. He asked me to put together a security bloggers network.
I still secure was a security company. So I reached out to a couple of my friends and I did that. And as I said, this is about, oh, it's almost 20 years ago now.
And, uh, we, we put it together pretty quickly. We probably had 50 to a hundred security blogs syndicated in there. And, um, this is around, as I say, 2003, 2004.
Um, and then we decide, wow, you know, and the security bloggers world was happening at the time. There were, Martin McKay had the network security blog. Mike Rothman, security Insight, rich Mogul Securosis, um, uh, Bruce Schneider was, was blogging of course.
Probably the biggest one was Brian Krebs, our friend Brian. Brian was still, I think at the Washington Post at the time. He was, yeah.
But, um, anyway, we quickly gathered this community that, that in retrospect was like a who's who of of bloggers. And we decide, you know what, it's time we meet in person. Let's, let's grab some beers at RSA this year.
And we, we put it out there that, you know, everyone who blogs security is invited to this bloggers meetup. And before you know it, companies are reaching out saying, Hey, I heard about this. We'd like to sponsor it.
We'll buy your beer for you. You don't have to ask me twice. Um, so we had the very first bloggers meetup, I, I guess it was either 2004 or 2005, I don't remember now.
There were probably about 35 or 40 of us that got together. And, um, you know, that, that's where it was born. From there, the Security bloggers network quickly grew to over 400 security blocks.
'cause blogging became very popular. And the Security bloggers meetup became an annual mainstay event at RSA, where those core people. And it grew, I think at the biggest, we probably had 250 people at the party, those core people.
It was the best event of RSA week. It was a marketing free zone, no sales zone, chill out, talk to your security friends and, you know, and have some fun, good, good drink, good food, good people. Um, fast forward, by the way, did Costal Law then sold a feed burner to Google for like 80 or $90 million on like zero revenue.
Um, crazy story, but true, about six months later, I get a call from Google and they said, Hey, Dick Costlow gave us your name. You know, we, we own Feed Burner now. We don't know what to do with the security bloggers network.
Would you take it back? I said, sure. You know, I, I, I created it.
I'm happy to. And I took it back. This was probably 2006 or 2007, and at that point, I, I put the security bloggers network feed, which was just a syndicated RSS feed out into the wild.
Anyone could use it, republish it, do whatever. Um, but I always thought it was a tremendous, tremendous, uh, uh, you know, a a a re reservoir of information. What a great resource.
com launches March of 2014. Within a year, I'm thinking, what's the next site we should do? Well, I'm a security guy.
I, I want to do security. And we come up with the notion of Security Boulevard. But what made Security Boulevard special is I took that security bloggers network feed and made it the backbone of Security Boulevard.
So today there's still, I think 300 or 350 blogs in the security bloggers network publishing anywhere from 20 to 40 articles a day on, on Security Boulevard. And it's why we have probably the most content of any site out there when it comes to security. Um, and it, and it's, it's real.
And it has been a you to every single person who's ever been a member of the security bloggers network. But, you know, times change, times change. First of all, not everyone blogs today, we have people who do podcasts and videos and newsletters and, uh, they create content, you know, on TikTok and social media.
They create tech, uh, content for tech vendors like White Papers and eBooks and infographs and any number of things. So calling it the Bloggers Network was kind of old. And speaking of all the last couple years, even during covid, when, when RSA was open, the last two years, we, we had our bloggers network and it was great.
'cause our core people, about 75 to a hundred of 'em still come down. We love getting together, but we've been doing this for 20 years, and many of us have been in the industry much longer than that. We want to bring in fresh blood, we want new people, we want new security content creators to be part of this, to, to take the baton, to take the torch and carry it forward.
So, long story short, that was a very long story, and it wasn't very short, but the, the, we've renamed the Security Bloggers Network as the Security Creators Network, still the same great blogs that were there before you could still join. And if you publish any kind of security, you can, uh, security content you can apply to have that added to the Security Boulevard site. And for RSA this year, as we do every year, the Wednesday night of RSA, this year it's March 8th, we are having the very first Security Creators network meet up, um, May 8th, uh, May 8th, excuse me, not March 8th.
Yes. And, uh, it's at the Tonga room, which we're also kind of building on the old Tonga Con, uh, vibe that Jack Daniels and, and some of those folks put together. And a shout out to Jack.
I don't think he'll be at RSA this year. Um, but anyway, you're all invited. You could look at, at the websites, you could Google it.
There's a Eventbrite page. We'd love to have you there. We are looking for sponsors, as we always do for the Security Creators Network.
This isn't a moneymaking thing for Techstrong. We, we throw money into, it's just still the same old story. We're covering the beers.
So if, if you're interested in that, reach out to me as well. But that, that's Mitch, did I miss anything? No, I love to hear you recant the story, and I've heard it many times, you know, which is on, and I love hearing it.
What's amazing to me is that I think the spirit of what started it was a group of us saying, we need to, we're getting in security. We gotta share this information, right? We're all kind of battling the same war, battling the same wars, and trying to figure out similar stuff.
And we can go to RSA and listen to each other's talks, but, you know, we're, we're blogging now, let's put this together. And it was a pretty altruistic, you know, community-based thing. And I think that community is still, is what's really held it together.
Yes, it's great content, it's great people, but it's, it's both collaborating together and sharing that which is what the network is, and expanding that to podcasts and videos and, and newsletters and all different kinds of content, um, just makes it a wider audience. And frankly, I mean, one of the benefits to you and I was, that also helped our, our profile in the industry. Oh, absolutely.
Increasing that, I mean, mm-Hmm. And people are doing that today. That's one of the inspirations for doing a podcast or, you know, doing these kinds of activities.
So we encourage you to join. We would love to have you, uh, be part of the network. Yep.
Two things I I left out there. I do wanna mention, one of the things that made the Bloggers Network Meetup, uh, pretty cool was we used to do the security bloggers awards. And I always thought they were tongue in cheek, but a lot of people took 'em very seriously.
We wanted to do it again for this year, but we're not gonna have, we didn't have enough runway between getting the, a place, the Tonga room and doing everything. But next year we will be back with a vengeance and we will be doing the Security Creators Network awards. And then lastly, and maybe most importantly, as I said, this isn't a tech strong only thing.
So I reached out to my friend Gianna, who is with the, or runs the security marketing professionals or cyber security marketing professional society, and they are partnering with us on this and producing it. Gianna and her team will help a lot with it. And don't be fooled because they're the marketing people that this is now becoming a marketing heavy event.
It's not, it's still a no marketing zone, but they have great connections into people creating security content today. And they also have a lot of people kind of coming up in the ranks. And I think they're a great organization for us to partner with to revitalize the, the meetup and, and bring new blood in.
I mean, we, we want to see new people come have some drinks on us. Yeah. A I think it'd be worth, and I know you can't name everybody, but there's some folks like Jennifer and people like that.
Yeah. Part of, yeah. People who were instrumental in, you know, my, our good friend Jennifer Legio, media fighter, we quite frankly, Mike Rothman, rich Mogul.
And I wrote her coattails for 10 years making this party. Jennifer did the whole thing. Um, but Mike Rothman, rich Mogul, I think I met, mentioned Martin McKay and Bruce Schneider and, and Brian Krebs.
People like Graham Cluey though, um, Troy Hunter from Microsoft always won a lot of awards. Uh, you know, Andy Ellis, Jack Daniels, I mentioned. Um, just trying to think of Jeremiah Grossman, Robert Hansen, ARS Snake, I mean, just a who's who of security, you know, that we saw Chris Hoff the Hoffmeister right.
Early on. Chris was, was huge in that. He was one of the best bloggers out there.
Um, so many more. Alex Hutton, I, I could probably go on forever there. There's actually a Facebook page, uh, security bloggers meetup where you can see pictures.
I happen to look at it yesterday to make the event, right. I've got pictures down there from 2007 to oh eight. I had so much hair.
Um, but anyway, um, do check it out if you're, if you're a cyber professional, if you create content around security, be part of it. That's my public service announcement for today. Anything else?
Well, I think it's really timely that you changed the name I blog. When I think of blogs, I do think of the early two thousands. Yeah.
And everybody had a blog. So content creation creator's network is great. And I also wanna point out kind of connecting it to our early segment about AI and how we don't know what's true and what's, what's real.
Because we're all just virtual and online. I think it's terrific that you're doing this in person event where the people that you, you read their blog, you don't really know them, and then you get to meet face to face. Absolutely.
What an excellent opportunity. And I will tell you the network that was built through this, I, I don't mean the bloggers network, I mean, the personal networking that goes on has really fueled, it's fueled tech strong. It's fueled my career.
It's fueled Mitchell's career. And a lot of 'em are really great friends. And some of them we only see once a year at RSA at the meetup and others, you know, we're, we're working with or, or talking to all the time.
But it is a big part of not only our network, but just our colleagues and friends that we've had for so many years. Yep. The labor of love.
Alright, I think that's gonna wrap our Textron gang today. I was, I'm sorry I was a little subdued there for a while, but whatever. Uh, I thought you were gonna get emotional there for them.
I, I was holding back. It's a Nice story. Um, but it is, it's a true story.
Anyway, we have a great lineup of Tech strong TV besides on the gang today. Mark, thanks for joining us. Hey man.
I, I know we're getting, we're about a month, well, a little more than a month out on, on the AI event. You want to give a quick update? Quick?
Yeah, yeah. So we have the Artificially Intelligent Enterprise Conference going on online May 21st. We're adding folks from Amazon.
We're adding folks from the practitioners that we're at large banks. They're talking about how to use generative AI from a firsthand experience. So, uh, if you get a chance, uh, go to, uh, tech Strong events, check us out, sign up.
Um, it should hours per half of the world. So you'll get to see, you know, a lot of different things, whether you're a developer, an executive business person, or a DevOps person. Gen AI for DevOps is one of the topics.
And then it will repeat another 12 hours for the other kind of like how the eclipse goes around. That's all right. And you can get to the Tech strong events, but Mark, what is the URL for the event, isn't it?
It is the AI enterprise online. So yep. The AI enterprise online, The THE, the AI enterprise online.
You could go right there, you know, registration's free. We'd love to have you on there. We really want to make this the biggest AI event out there.
So sign up. We, Mark's done a great job. If you, you don't follow his artificially Intelligent Enterprise newsletter and stuff, you're missing out on a lot of great AI news.
I know you knowhow run up for that for sure. Yep. Alright.
And happy Thursday everyone. Enjoy the rest of Techstrong tv. We're not live on Friday as usual.
Have a best of, but we'll be back at it on Monday. Thank you. Cloud native now is the web's leading resource for the growing cloud native ecosystem.
com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes serverless, cloud native application development, microservices, service mesh, cloud native security, and more. Stay on the cutting edge of modern application development at Cloud Native now. Hey everyone, hope you enjoyed the Textron gang today.
We had a great discussion with, uh, my friend Mark Hinkle and Mitchell and, and Bonnie Schneider. But now it's time for the rest of our Textron TV show today. Um, first up is one of my favorite interviews.
I do it every year right before RSA. And this is with Cecilia Marna. Cecilia, uh, is heads up the innovation and, uh, and scholars at RSA conference that includes the sandbox and startup stuff.
And she came on to tell us what to expect today regarding that ad RSA this year, which starts May 6th. Cecilia's a great person. She lays it all out.
This is a great interview. Check it out. This is Textron tv.
Hi everyone. We're back here on techron tv. You know, it's getting near that time of year and I am not talking about Christmas.
I'm talking about RSA conference. It's about a month away. We are pumped here at Textron.
We've got so many things going on for RSA. We've got our DevOps Connect DevSecOps seminar again. I've got, got an amazing lineup of AI speakers headlined by the very famous sci-fi author David Bri, who's multiple Hugo Nebula Awards, PhD from nasa, jet Propulsion, JPL movies, books, everything.
And we kind of great speakers. In addition to that, we're gonna be addition to that. We're gonna be live at Techstrong at, uh, broadcast Alley all week.
Uh, we're putting, I have a panel I'm doing on what's next in DevSecOps. This woman right here is the lady behind the Sandbox Innovation Sandbox. And everything else that's been grown was originally just a sandbox.
Now they've got all kinds of programs around this. Um, I've had the pleasure of interviewing her for years, literally on our show. And to me, RS a's real when Cecilia's on, let me introduce you to Cecilia Mar.
I hope I do it right. You did great. You know, after a certain amount of years, it kind of sets in.
Cecilia, welcome. Its Off your tongue. It rolls off your tongue.
Well, I'm just back from Paris too, so I, I had a little practice. Anyway, Cecilia, it's so great to have you on. You look fantastic.
How's everything? Things are great. It's such an exciting year.
I know this is crazy, but, and I say this every year, so I feel kind of like I gotta, you know, shake it up a little bit. But honestly, this is gonna be the goat. We have so many great, amazing things coming this year, including you, Alan, you're gonna be there.
We're excited. We have a crazy great lineup for our keynotes. And we just announced the top 10 for Innovation Sandbox Contest.
It's gonna be fun. I can't wait Either. Can I?
I I, you know, I just, I can't wait. Um, Cecilia, we, we've got people out here. Some of our audience, a lot of our audience are cyber folks and they'll be at RSA.
A lot of 'em are DevOps. They may be at RSA too Cloud Native Digital Transformation, right? Of course, AI folks, but not everyone is probably familiar with the Innovation Sandbox program that you've been running over at the RSA conference for, what is it now?
It's gotta be 10 years more, 15 years, 18 years. Alan, Alan, you're making me old Man. No, you weren't doing it all the time.
I know. I was saying that actually the contest itself is 19 years old and, um, and it has had just an incredible run of picking really important companies that are shifting and changing our industry. So it's so amazing to be working on this program.
I like it a lot. So, you know, RSA conference is committed to supporting and amplifying innovation. We try really hard to help our community members hear from companies that are developing novel approaches to attack the complex problems facing our industry.
And the Innovation Sandbox is the, the leading platform where we just announced the top 10, as I just spoke about, uh, in, they will be on the stage on May 6th. And so a super fun group of people, you know, this co this competition has actually had the luck, or not necessarily luck, just amazing track record of all of the companies that have come on here. There's been 80 acquisitions over 13 and a half billion in investments.
We've had Phantom Win Big ID exons recently, TALEN Security, and last year was Hidden Layer. So those are names, you know, they, they came to our stage in the beginning of their launch of their really big, uh, uh, announcement to their, to the whole audience. And then it really has shown us how important this contest is at in launching these these companies careers.
Absolutely. You know, and it is, it's, it's, it's, it's become the showcase for up and coming security companies and and what a feather in the cap it is. Even not even a win.
Even to make the top 10 finalist list. The top 10 Is, is, I mean, yeah. Yeah.
13 and a half billion in investments. Those guys have done very well. Extremely well.
Absolutely. It, it's crazy. So let me ask you, how do you want do this?
Should we, do you wanna run through the whole top 10 or do we say, if you want to see it go to the RSA site? The RSA conference site? So yeah, your, your call.
I, I kind of wanna do two things. One, I wanna talk a little bit about the trends. So yes, you know, when you're thinking about what is the most impactful technology that's just happened in the last 24 months, it's artificial intelligence.
And so in the top 10, you're gonna see many of the companies either talk about, you know, large language models or they're gonna be using Gen AI in order to really, uh, increase the security teams productivity. You have companies that are creating solutions to help you find the fake deep fakes, uh, the applications to ensure that you're, you're going against the adversaries that are using these technologies as well. I think some of the other pieces that are really important is just the judges that are here, not only our veterans onto the ISB panel, but they're also representative of leaders in the industry from different voices and different perspectives.
So when they were choosing these companies, you know, you had a venture capitalist with em, Chandra from Greylock, uh mm-Hmm. You had large security company strategist with Dory Do from Checkpoint, uh, who's the chief technology officer over there. You have Nilu Howe, who is, um, who is on the pulse of national security.
You have a successful entrepreneur, Paul Kocher, who has demonstrated how to take a company out from, uh, from the nascent stages all the way to exit. And then you also have, uh, Nazarene, who is the CISO at Verizon. So all those perspectives came together and they helped choose the top 10.
And I'm not gonna highlight any specific company and it gets too long if we actually talk through the names, but go check 'em out. It's gonna be a really incredible lineup. I love the companies that are gonna be there.
Where can we go check 'em out? So you go to, um, you go to the RSA conference website, you go to the events page, and you get innovation. And not only sandbox with the top 10, you'll see their logos.
Uh, you can also check out a little bit more detail if you read the press release. 'cause we did put a small snippet of each of the company's names, but off of our website, you can actually click through to find those companies. Um, but when you're there, you can also be checking out all of the other innovation offerings, because this year we have some really cool things coming with Launchpad.
I'm just gonna briefly touch on that because I am really excited about the judges there. It's Enrique Salem from Bain Capital. Sure.
We have Sarah Gao from Conviction. She started her own firm, but she's a Greylock Venture, uh, veteran. And then you have also Bar Mfta who used to run, uh, alien Vault and now has started Ballistic Ventures.
So, I mean, again, like just Stellar. And before Alien Vault, he had another good company before a, so I would, full disclosure, I was on the board of advisors of Alien Vault and, but, um, um, good job, Alan. Yeah, no, you did great Sell.
Good Sell. But the company they did before was pretty good too. Oh.
Um, they had a good exit anyway. Yeah. I mean, these are, these are giants in the community.
Yes. Cecilia from people who, again, who may not be familiar, the difference between Sandbox and Launchpad. Okay.
You know what, I'm gonna do three there because Alan, I have to tell you, we did something about naming that has been, uh, a little bit of a challenge for us about Sandbox. So the Innovation Sandbox Contest is our 19-year-old contest. It's taking companies that are in their, they're ready to go to market.
They have the product that is going, that is, has been launched, and they have the team in place in order to actually make an impact in the cybersecurity market over the next 12 months. Launchpad is aimed at an earlier stage company. It's a company that probably doesn't have their product out, or if they do, it was, it's coming out right before or at conference.
And the goal here was kind of building out something where we could demonstrate where trends were happening earlier on. With Launchpad, it's a shorter contest. There's only three companies that are gonna be there.
And basically it's a little bit more like Shark Tank, where at the end of the, at the end of the pitch, he will ask the different, uh, VCs, are you in? Would you wanna see this company again? And I have seen those companies and it's really cool to see some of those solutions that they're coming out with.
So I don't know who's gonna be picked, because that's happening on Friday. You have to wait till next week. Mm-Hmm.
But, uh, that's gonna be, that's what launchpad is. And ISB has just, um, has just announced their top 10, so they're ready to go. You can check those guys out.
Great. And the Last one, I forgot, so Sam, Oh yeah, the third one last, Because these are your friends, Alan, this is where we have created this like kind of hands-on zone. It's, it's in the actual location, the actual location close to Innovation Sandbox.
But it's in the zone where what we've asked is to have different, like basically def com villages come in and do some hands-on activities. And so you have the ICS village and the IOT village and the AI village, and they all give you like a little mini sampling. And it also has talks on a stage that are, are more aligned with some of the, you know, cutting edge research.
And then you have, oh, and Cloud Security Village, there's eight villages. Oh. And including, uh, the Idaho National Labs and cisa are bringing an escape room.
So you I playing the escape room. I know. Oh, that's, it's super fun's fun.
It's super fun. So I, I'm excited for this year's, uh, innovation area. It really is gonna be packed and fun and come, come play with us.
Absolutely. You know, last year at RSAI, um, I felt like wow, COVID ISS in the rear view mirror. I think we were back up to like 40 something thousand people.
Uh, it felt like RSA again, this year though, I'm expecting a record breaking. RSA How are, can you comment on that? How, how Our numbers, our numbers are good.
Our numbers are good. I, I'll, I'm not a betting person because I don't like to do that. But what I can tell you is we are trending very well against our own expectations.
And so I feel good about, um, do I about the numbers that You, I'm so looking forward is what I'll, I I hear you. You know, we'll be there all week, as I said on broadcast Ali. Uh, and I'm, look, RS a's a highlight for my ha has been for many years.
Um, Cecile, you know what I realize, not everyone I do, we tell 'em go to the RSA conference website. us Now? I forget.
com and then if, if you go up, you can see the events and in there in one of the tags. We'll, conference slash usa you know, events. But Now that we've, now that we're back, Yes.
Can we start doing RSA again in, in other places? Singapore, Abu Dhabi, we've done in the past London. What are, what are our plan?
And I realize you're not the be all and end all for all things RSA conference, but, But what do I know? What do think, what Do I know? What do you know?
What do you know what, just between us, I'll give you the inside scoop. You know, we do have a vision to really start spreading our wings again. Uh, it's gonna take, you know, a year or two to kind of get ourselves back to where we, back to finding the locations and, and being strategic about it.
Like finding how to really increase you the community's value out of this. Our goal is not to do conferences. Our goal is to build a community.
Yep. And we can do that. And we need to get to those locations in order to do that.
So our objectives in the next 12 months is to really kind of fig, flesh out where we should be going. And that's where I'll leave it, because it's, uh, alright, Well look, it's Discovered. Hey, hey.
You've got a lot of ideas here, though. We're open to getting, uh, feedback. Oh, I have ideas.
We'll give them to you. But, you know, it's a dangling metaphor. As I said, there's nothing matter with Amsterdam, Paris, London, Prague, any, any of the cities in Spain are nice.
Yes. Um, but we'll talk, we'll talk more, um, Cecilia all kidding said, we gotta wrap up. But first of all, congratulations on what you're doing with the sandbox and, and launchpad and everything.
Thank you. It it, it serves a very important purpose because innovation in cyber doesn't necessarily, doesn't usually come from the companies up here who maybe are supplying judges. Innovation in cyber starts at the grassroots level with startups and with new companies, with new ways of looking at things and new ideas.
Right. And so it's, it's so important to give these companies a glide path to take off. And, and this is the best one there is.
Yeah. Thank you. I, I mean, we've done a lot of effort on this and we're still building it out.
We really do want to amplify innovation as we, it's one of our missions. And I really believe that the creativity from the good guys is absolutely essential to go against the bad guys. 'cause they are creative, but they Startup they are creative funded.
Yeah, Absolutely. And our startups are nimble, and the people have great mission, great vision, and they, it, it's just been really fun to spend 10 years in this and see just how far we've come and what we're doing next. And I, I, I really am proud of this cybersecurity community.
It's always amazing to me how they step up and they, they pivot quickly. They adapt new technologies, they build new solutions. And if our whole idea is to help that community and to pro provide them this platform, then I hope we're doing the right thing and we're doing a good job.
And, and, uh, again, we'll take feedback. Absolutely. Great, Cecilia, best of luck.
Can't wait to find out more and see, and maybe we'll be interviewing some of these finalists as well before. I hope you do say, I Hope you do we'll. Uh, I'm gonna talk to someone I know who can help me there.
Um, Cecilia Mario, yay. Senior Director Innovation and scholars of RSA conference talking about the innovation early stage startups at RSA conference coming up in about a month. It all starts on May 6th, Monday, May 6th through Thursday.
I I guess that's the ninth, Cecilia. Great seeing you. Great seeing you, Alan.
I'm looking forward to seeing you in person. Me too. We're gonna take a break here on Techstrong.
We'll be back in a minute. Next up, I've got my friend Mav Turner, who's the Chief Product and Strategy Officer for tricentis. Mav is gonna discuss Tricentis latest state of mobile application quality report with some interesting findings there.
Here's Mav Turner, This is Techstrong tv. Hi everyone. Welcome back here to Techstrong tv.
My next guest is my friend Mav Turner. If you've been watching Techstrong tv, you've seen Mav on here a few times. Mav is the chief product and Strategy Officer at tricentis.
Good partner of ours here at Techstrong, as well as just the wealth. They're the worldwide leader in continuous testing. Right.
Um, hey Mav, welcome back to Techstrong tv. It's great to see you. I hope all's well, Everything's great.
Thanks for having me, Alan. Uh, always fun to talk with you and your audience here about, uh, what's going on in the world of quality engineering. And, uh, again, for those of you who may not know Tricentis, uh, as, as Alan, uh, graciously introduced us, uh, the worldwide leader in continuous automation, uh, in addition to automation, a lot of folks are, are using us for test management, performance engineering.
Uh, we have quite a broad portfolio. But if you're thinking about how do I deliver quality with software, uh, Tricentis probably has something for, for you there. Absolutely.
com of course is the website. Um, and you can go check it out and, and that, that's a, you know, ma I noticed, I I'm at a date, you call it worldwide continuous automation, not just testing, Right? Yeah.
We, we, we've really expanded beyond just the kind of functional testing concept, right? If you go back to our founding, that's what most people know us of, right? I'm doing testing, I'm trying to move from manual testing to continuous testing, that we've been really big in that for a long time.
When we think about the quality engineering process and we think about what needs to happen to deliver high quality software, that's where we get into how do we think about test management? How do I think about performance engineering? And to segue into some of our conversation here, you know, as mobile becomes more and more important, how do we make sure we have coverage of all the technologies in the enterprise and in your application environment to ensure success?
And so that's the continuous evolution for tricentis here. Excellent. Glad I caught that.
All right. Mav, recently, Tricentis came out with their state of mobile application quality report for 2024. First of all, it, that's a mouthful.
What exactly is the report on? Yeah, so when we think about what we need to do to help our customers, obviously we're talking with them all the time, or we're talking with non-customers, right? We're trying to understand where, understand where there are the challenges and how can we best apply our resources, our technology, uh, to help.
Right? And, uh, so in addition to all of our one-on-one conversations with customers, we like to do industry surveys to help inform that strategy. And so to your your point about the long title here, um, we just wanted to understand from a mobile perspective, um, where everybody was, where do we think, uh, mobile quality is?
Where do we think the gaps are? Where do we need to focus? Um, and, and get that kind of different perspective of, of research.
So, uh, yeah, we fielded this report, um, globally to understand. 'cause sometimes you'll get interesting data from different parts of the world. Um, but just to understand, yeah, what's the state of mobile application development and mobile quality?
Okay. And is this report based upon like survey data or interviews in depth interviews customer data somehow, or, you know, some other proprietary All of the above. Exactly.
Global survey, primarily survey. Um, so the mm-hmm. The survey's informed by the deep 1 0 1 conversations we have with our customers all the time.
And so that allows us to kind of frame out the questions we want to go deeper and more, more broadly. Um, so usually when you think about research methodologies, you think about, you know, how can a one-on-one qual qualitative conversation, uh, inform and drive a more broad scale quantitative analysis of the market, which then actually feeds back into our fall, our, our, you know, uh, future, uh, qualitative research with, with customers. And so it's a continuous loop.
It never, it never really ends, uh, which if you're doing it right, uh, but yeah, this was a, a, uh, global market survey that, that we sent out a bunch of questions on to understand, you know, a couple of areas again, where everybody is today, um, you know, from a, you know, what are they doing? What do they think the impact of, of quality is, and the mobile experience specifically. And we think about, um, how AI is impacting, uh, their development processes and where are they using it, uh, what their, do they think it's good or bad?
Um, why, why is it important? Right? Is is it really important, it, should it be a priority or not?
What, what, what do the, the, the people think when we are, we're doing these mar market surveys, and then what's the future? Where are we going with, with, with quality? How do people think about their strategies and their roadmaps and, and how it impacts their, their business growth?
Excellent. Very cool. You know, do, do you have a sense in, in terms of the survey size of the audience that responded here?
Yeah, it was over a thousand people. Uh, like I said, global survey. So we have hundreds of people from the us, from Germany, um, um, and, and Asia Pacific and Singapore.
Um, lots of markets that we wanted to make sure to hit. Um, you know, the, the interesting thing I'll say from, from the size of the, the thousands of developers and IT professionals that responded was, um, that, that most everybody's kind of struggling with a lot of the same things. And, and, uh, you know, there, there wasn't one pocket where, you know, um, uh, any one country kind of stood out.
Um, the one area I will, I will kind of peel back on that global topic is around the, um, sentiment around ai. And I'll tell you, I was somewhat surprised by this, and I think it's a, this may end up being a whole top track on this one topic, but, um, when we look at AI in the sentiment, and we split that out by country, um, the most positive sentiment was out of Germany about the impact of positive impact of ai, um, in the context of mobile quality. And the reason I'm surprised by that, I'm curious, Alan, if you have any reactions to that yourself, was, um, generally we see more skepticism from that market, right?
More, more concerns, uh, particularly around data privacy and, and the risk of ai. But, but what I, what I've talked with a lot of our customers in that market, um, while they still want to apply this rigor to the adoption of ai, they believe and want to be leaders in the market when it comes to leveraging AI and see this as a huge opportunity, and not just in, in Germany and, and, and other European countries as well. Um, so they don't wanna feel like they get left behind here, right?
So they're very, very, uh, forward adopting here. Um, actually the US was, um, had had the least positive, I don't wanna say it was negative, but about 81% of people in Germany had a positive sentiment on the impact of, of AI and quality, whereas in the US is only 69%. So there was a pretty big distinction there.
Um, right behind Germany was Singapore, um, and then the UK and the US were kind of notably, uh, further behind. So I don't know your your, your reaction to, to some of those, those points, but I thought it was interesting. Um, I'm, let me say, I'm not surprised on, on that last one, right?
I, I, you know, it was interesting. I recently came, I was out in Paris for CubeCon, and then from there we went over to Sicily and Rome and some other places. And I, I travel to Europe a bunch and I'd go to Singapore.
Yeah. Yeah. Someone's got to do it.
Uh, yeah. We appreciate you doing it. Yeah.
And then, yeah, I've been, I usually go to Singapore like once a year as well, and in that area of the world Pac Yeah, Asia Pac, you know, I, I think it reflects their usage. I think it reflects their values. I think it reflects their goals.
Um, that being said, for whatever reason, you'll see crazy innovation in the US and, and the UK kind of does mirror us a lot more than it mirrors, let's say Germany. Right? Agreed.
Um, so I, I'm not saying that we're laggards or that we care less or we're, you know, but are we less optimistic or do we not even think about that? Just full speed ahead and damn the torpedoes Ready? There is some of that too, right?
Yes. Yeah. Yeah.
You think about it later. So what if we dive in the pool and find out at bottom, there's no water in there. Right?
Right. It's all good. Yeah.
We were the first one to dive in. Yeah. Um, it, it's funny.
Hey, you know, I do wanna mention though, before we jump more into the report, anybody who wants to go grab the report themselves, it it, I will put this, we'll try to put this in the, uh, notes on the, uh, video as well. com/resources/mobile-application-quality-report. And you can get it from there.
As I said, we'll do, we will try to put that in, in the notes for today's interview. So, Mav, what were some of the other, like, big takeaways here? Yeah.
And kind of moving out of the, the AI question. 'cause again, that's, that's, you know, usually a, uh, you know, uh, e evergreen topic. Everybody wants to know about that.
But there's a lot of other good, good nuggets, uh, we found out here as well. Um, we, another interesting thing that I got out of this report that, you know, you get a lot of anecdotal stories from customers, uh, but to do a survey at scale and you get responses that, um, when we talk about revenue impact and business impact of low quality, 'cause this is something that I think a lot of, we go down to the development teams, the application teams, they usually get a little bit too far from. And if, and if they can kind of figure out how to tell that, that story about how their work impacts the bottom line, it really makes a more impactful story for what they're doing and why they're doing it and how many resources they need.
But we saw that, uh, over 90% of the respondents se estimated that this poor quality experience cost their business up to two and a half million dollars in revenue. And so being able to quantify why it matters, why taking the time, um, why having the proper environment, the tooling, the people, the training to be successful can actually matter to the business. And so I was, I was interested to see that very, you know, kind of clustering of responses around, around that number.
So obviously some people said higher, some people said lower, but, uh, but it was a pretty strong signal there about real business impact being felt, uh, around for quality. Yeah, absolutely. Absolutely.
What else? Um, and, and I think that's really, you know, paired well with the fact that, you know, only a quarter basically said that their current strategy exceeded their expectations. So you say, you know, we know we're not doing well, we know it's having an impact.
Okay, so now what do we do next? Right? And so, hopefully some of the things we talked about here, and if you go get the report that you just mentioned, people can start to figure out, how can I make sure that this is elevated to the right priority level of business?
Because the benefits are great, right? Um, if, if, if, if mobile is a key part of your business, um, then ensuring high quality by understanding the processes that you need to deliver that quality, having the right tooling, um, having the right, having the right just quality mindset overall. Um, if they can move to more automated solutions versus, look, we, we all do what we can.
We, I talk to some customers that say, our testing process is we deploy it to our internal employees, and they use it before we deploy it out to the field. And, you know, that's some, some companies that's what they do. But as you move from that manual testing, ad hoc testing to a more automated testing that allows that human resource resource to really spend time doing things that, that only humans can really do with the exploratory testing.
And, and that, that kind of same theme that Tricentis has been repeating again and again around, um, automation is, is still very critical. And we find that mobile applications are much less mature. Um, and mobile application development teams much less mature in an automation perspective than, um, web or, or desktop based, um, application development teams.
Absolutely. Very cool stuff. Um, let's talk about mobile applications versus, I know you wanna call 'em non-mobile applications or traditional, you know, there was a time map, uh, I'm gonna say seven, eight years ago, where, I mean, clearly there was this fork in the road between mobile application development versus application development.
A lot of, there were a lot of companies that focused solely on mobile app development, mobile app security, mobile app, this mobile app that it's my, and this is more of a gut feeling. I don't have kinds subjective numbers or objective numbers to to, to show to you. Um, but it, there seems to be more of a, a coming together, right?
That mobile is not just a totally different animal that it was years ago. I wonder if that somehow is reflected in here or maybe just from your own, you know, experience. What do you think?
A couple of things there, right? If you, if you go back to, and I'll use iPhone, obviously Android has its own similar story, but slightly different. Um, you know, the original launch of the iPhone and, you know, weren't gonna have third parties being able to build custom apps.
Everything was just gonna be developed by Apple. And then opening up of that app ecosystem, and I think around the same timeframe that you're talking about where you see this explosion of application developments, everybody's getting into it. Um, they're building native apps and, and then, and then Android, I mean, as a massive market, right?
Much larger than, than than Apple. And then you see, okay, now I have to figure out what, where my customers are, what devices and what, what, what I've seen is in the last couple years that we've really invested more in mobile, um, is really the, you know, react native, na native, these hybrid applications that have web and some native components. Teams trying to, um, kind of build once, deploy twice, right?
Instead of having to have, here's our, you know, iOS development team and here's our Android development team, how can we, you know, use frameworks like Flutter to build an application, um, effectively and reach these audiences? And, and not to get too much into the weeds, but it, it really comes into an overall well architected solution. When you think about the backend, you think about the customer's experience, if you can abstract the business logic from the presentation layer, effectively, you can go really fast into building front ends, um, and the web, web UI or, or even a desktop app, maybe you have the, you know, uh, desktop apps you wanna run, um, and a mobile app.
But if they're all hitting those same backend resources efficiently, um, then you really maximize your market capture. And, and I think through a lot of these frameworks and a lot of the, it's much easier to be an application mobile application developer today than it was 10 years ago, for sure, seven years ago. Um, but there's still a lot of challenges.
And, and I think what we're, what I'm seeing anyways is, um, with, with some of the advances in maturing on the development side, you naturally see more maturity on the testing and quality side that comes around that as well, right? But, but usually that is a little bit of a laggard compared to the development tool stack, which is iterating very quickly, um, the frameworks everybody's using. And so when I think about it, I think, or when, when I see what, what's happening with our customers, um, I expected a lot of more just native development teams when we, a couple years ago when we kinda really started to go deep.
And what we've ne mostly seen is the use of these frameworks, um, to actually build, um, build once and then kind of take advantage of these hybrid apps, which is much more prevalent than I, than I first suspected a couple of years ago. Absolutely. Hey, Matt, we're about outta time, actually, we're over time.
I apologize. We got kinda waylaid there, but, um, look, it was interesting stuff again that this is the t Tricentis State of Mobile application quality report for 2024. com/resources/mobile-application-quality-report map.
Thank you so much. Hope to see you back here soon on Text Drug tv. Say hello to all our friends at t Tricentis.
Will do. Thanks for having me, Alan. All righty.
This Alan Hummel, we're gonna be back here on Text Drug TV with even more news and information in just a second. Standby. I am Bonnie Schneider, sustainability contributor to the Techstrong Group.
I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry as a leader in the industry, and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong Research Next Up is one of my favorite, uh, video shows that we do here on Text Drunk tv, it's CD Pipeline. We do that in, in conjunction with the good folks of the CDF, the CD Foundation.
And in this one, well, this is a contentious one. We had a couple of folks that run on platform engineering. It's challenges, it's efficacy.
How does it work or interact with DevOps, how open source ecosystems are driving it. Great, great conversation. You don't want to miss this one.
Check it out. Hey everyone, welcome to CD Pipeline. Uh, if you haven't watched this show before, I should tell you my name is Alan Shimmel.
I'm the CEO of Techron Group and cd. The CD Pipeline is a joint, uh, adventure, venture, adventure, whatever you want to call it, between, uh, Textron Group and our good friends at the CD Foundation, which of course is part of the larger Linux Foundation. And, and if you're not familiar with the CDF, you really should be, they're kind of the leading organization that is advancing the whole CICD, uh, movement.
And they actually are responsible for managing many of the leading open source projects within the CICD world, including kind of household names for those of us in here, such as, um, Jenkins, Spinnaker, uh, and more. There's about, I think, eight or nine different projects within CD Foundation and we'll go over them. But if we spend too much time on that, we're not gonna have enough time to talk about what I really want to talk about today.
And that is the subject for this, uh, for this episode of CD Pipelines. And it's decoding platform engineering, a critical dialogue with DevOps and CD leaders. That aside, we're gonna dig into platform engineering and what do we really think about and how would it relate to CICD and to DevOps and Agile and everything else?
Let me introduce you to what I think is a monster panel we're gonna have on here. Uh, first of all, I want to introduce you to DSI ika. Hopefully I got that as best I've done so far.
dsi, welcome back to our show, man. It's great to see you. Why don't you introduce yourself.
Uh, thank you so much for having me again, Alan. I love being here. Uh, my name is, as you said, is DSI Ika, and I am the current board chair of the CD Foundation, as well as a member of the spinnaker Technical Oversight Committee.
Um, I'm just excited to be here. I'm just excited to be here and, uh, you know, waiting to see what the panel has to say. Thank You.
Hey, the dc not to put you on the spot, but I got three projects in and, and my brain pros. Yep. Um, do you wanna do the rest to tell, just to remind our audience the rest of the projects in CDF?
Sure. Um, so you mentioned Jenkins and spinnaker. We also have Ton orus, uh, shipwright, and of course CD events.
Um, all of the projects, like you said, are are centered around, uh, CICD. And we are trying not only to advance the, the, the community of cd, but also think about what's the next set of tools and beyond, and how will CICD impact platform and how should platform actually recognize and contribute to CI ICD. Um, and all of that is around the software developers lifecycle.
So that is, that is our main focus. Excellent. Missed a couple, My Friend.
I thought there were eight, but I look, he's the executive director. I wasn't gonna call him on it, but Gloria, go ahead. What?
Uh, but you know what? Wait till I come to you and you fill it in. I got you.
All right. Next up, let me introduce you to, uh, Nina Kani ne Nima Kani. Excuse me.
Yes, no problem. Thank you, Ellen. So, Nima Ani, uh, I'm a principal architect with AWS, um, and it's been three and a half, almost four years that I've been working with, um, you know, enterprise scale, um, AWS customers on DevOps and platform engineering.
Uh, we've been building a lot of solutions. I've been, um, a TOC member for spinnaker in the past. I have, uh, contributed to Argo cd.
Um, and recently we started the initiative called Cloud Native Operational Excellence that looks at building better DevOps platforms for enterprise scale users. And happy to be here to talk to you about DevOps, engineering. Nima, i'd, I'd love, I'm first of all thank you for being here, and I look forward to having your input on this.
Um, next up, let me introduce you to Tiffany Joha. Guys, I have to apologize. I have Invisaligns today and I'm still, they're two days old and I'm still learning to enunciate better.
But Tiffany, if you could pronounce your name and introduce yourself. Sure. Hi everyone.
Thanks Alan. Invisalign is tough. Uh, I've been there, done that as well.
Uhhuh, my name is Tiffany Chacha. I'm so glad to be here with you all. I am an engineering manager at Autodesk, and I lead the platform, um, Autodesk Platform services support.
So we work with dozens of platform engineering teams internal to Autodesk to represent our developer community, which includes over 200 engineering teams, and we help provide that initial support for all of their software delivery needs. So, touching on many of the tech stack that, um, here, the folks at the CD foundation are, are really helping to nurture and, um, and help the community, uh, work with, with different tools and, and for the purposes of, uh, better software delivery. So, super glad to be here with you all, uh, discuss this in more detail.
Tiffany, thank you very much. Yeah, I definitely think it's that, like the CHSH sounds that I'm gonna have problems with. But next up, luckily his name's fairly easy for me to pronounce.
Andrew Fong. Hey, Andrew. Welcome.
How are you? Hey, good. How are you today, Alan?
Good, good. Um, so I am currently CEO co-founder of pvoa. We are building intent-based delivery, so to as a force multiplier for platform engineering.
Um, spent most of my career in infrastructure, uh, from a OL to YouTube to Dropbox. And you know, we really think we're building a next generation of platform tools. Companies like use us to manage a hundred percent of their infrastructure in production at this point.
Excellent and welcome. Thanks, Andrew. Okay.
And then last but not least is my co-host, actually. And, and since our last taping, she has a new title and a new job to announce as well. We'll give her a chance to say it right here.
But she's all thanks to a lot of open source. She really helps in a lot of these foundations and a lot of capacities, my friend Lori LaRusso. Hey, Lori, welcome.
Thank you, Alan. And yeah, so I just, um, started with Perona. So it's all about open source.
I am the head of community and it's my second week, so stay tuned for lots of good things to come. Uh, lots of interaction with our users and I'm really excited to help, um, to help kind of shape the future of, uh, of Percona and their community involvement. That being said, I am here because I represent the CDF and Alan, you get everybody every time when you ask us to list the projects.
Didi, he did it to me, puts you on the spot, and you just forget some. I mean, there's only eight, but when I say only eight, these are eight amazing projects. And so let me just give you the list.
And I am cheating. I do have my phone in front of me. Oh, okay.
So No calculators. Yeah, as Didi said, we have CD events, uh, Jenkins, uh, Jenkins, X Ortus, screwdriver, shipwright, Spinnaker, and Teton. So we kind of cover the entire smorgasbord of CICD, and I am absolutely thrilled to have this, uh, conversation today, um, to have the spinnaker team with us, to have Andrew and Tiffany to really kind of dig in to this whole idea of platform engineering.
Excellent. com, I initially had a pretty visceral reaction to be platform engineering movement because I, I felt like they were, and maybe it was just a marketing play, you know, saying DevOps is dead long lived platform engineering, and I, it was marketing, I think, or maybe not. We'll hear what you have to say.
But over time, I've, I've softened and, and come to respect what platform engineering is trying to do. And I think it certainly does have its place in this continuum of how we build, so build and deliver software today. Andrew, I'm going to start with you if you don't mind.
And, you know, I, I'd like you to kind of succinctly tell our audience what do you think platform engineering is, or what should they think? What should they know platform engineering is, and how does it fit into the kind of, you know, into the, the, the bigger picture, if you will? So, I, I tended to think of platforms as sort of three levels.
One is sort of traditional, it, you know, where you have, you have the piece of software you install, like probably what we're all familiar with in the early nineties, early two thousands. Then we kind of moved to this DevOps world of CICD. I think that's kind of a level two maturity of like platforms.
It's like, let's get self-service. It's our i internal developer platform, IDP sort of discovery tools. I think there's like a third level of platforms, which I think is, goes very, gets flows, applies under the radar right now, which tends to be more about how you do app full cycle application development.
So how does your RRP C framework work? How does your, how do you handle monitoring? How do you build an entire end-to-end application?
Um, which is a very different place. And I think most organizations right now are somewhere between maturity levels of one and two in that mental model. Um, I think it's a good discussion today to see like, okay, you know, CDF probably focuses more on the level two versus sort of the level three, um, uh, like altitude.
But I'll pause there that I see how that resonates with people on the, on the panel. Guys, we reactions to that. Come on.
Someone's gotta have an opinion. Yeah, I, I think that's a, a good way to look at it. I, I will, I personally think that, um, the platform movement in itself is more of an obfuscation of the tool sets below it.
Um, and being able to have a rich set of tools integrate into the platform concept will be always be driven by the DevOps folks, will always be driven by, uh, CD folks who are trying to give excellence with the tools. Underneath. The challenge becomes how do you take, um, a lot of different types of tools, uh, you know, and then create specialized platforms that, that meet your service needs and your service goals.
Um, I, I think that's one of the reasons that, uh, the, the canoe project is so interesting. Uh, as they try and figure out, okay, you, you already have tools and things you'd like to use, how do we give you a platform on the fly with that that is, is useful and available? Um, so our focus of course, in the CDF is the tool excellence and, and having that ability to, uh, separate your software delivery, uh, lifecycle workflows, workflows, um, as well as making sure that the tools underneath your platform are excellent.
Fair. Anybody else? No.
So let me, let me jump in then. I've been known to have an opinion now on that. So Andrew did a good job of delineating different levels, if you will, uh, of, you know, of, of engineering, of platforms and, and how, how this plays out in my mind.
There's a couple of things here that actually are good things. Number one, I think one of the problems we've had in, in DevOps in general has been the move to just throw more stuff on the developer's back, right? DevSecOps?
Yeah. Let's make our developers security people, they're not security people. They, they care about security testing.
Well let the developers do more testing, right? Uh, the developers are probably the highest paid people in the food chain right there. The idea of just throwing more stuff onto their plate until, you know, the, the, the, the proverbial straw that breaks the camel's back, it doesn't seem like a very efficient way of doing things.
And that includes having the developers try to architect and maintain their platforms, right? So the idea of having an yet another team and, and the idea of building another silo, I get it, is anti DevOps. But the idea of having a team that helps facilitate a, a working platform and set of tools that the developers can then do what they like to do, which is code makes perfect sense to me.
I also think that a lot, and back to Andrew's, you know, kind of delineation of the different kinds of platform and platform engineering, I think a lot of the ops functions that we've historically had that maybe would give it short shrift in the whole DevOps movement are still very valid and necessary. And platform engineering gives those ops functions, a a new home, a new fresh breath, a new name, if you will. And if that's all it does, it's still helping shine the light on these very necessary, uh, functions, these very necessary tools and processes and so forth.
I think this is a good time for Tiffany to kind of jump in because this is in essence what she does, right? Like manages the team of, so, Tiffany, what are your thoughts on what Alan just said? Yeah, I actually, I love how everybody mentioned sort of two underlying factors when it comes to platform engineering that I, I'd like to highlight for anyone who's listening, the first being that sort of scale slash customer facing or developer facing aspect to it, right?
A lot of, like, I, I think there was a lot of initial pushback on platform engineering as sort of this replacement to DevOps. But when you think about it, the reason why we've introduced platform engineering or platform solutions is to better address the needs and concerns of the developers that we're serving. And so, in effect, dev platform engineering is almost like the DevOps practices scaled in a way to meet enterprise or bigger organization needs.
And doesn't have to mean that you have a thousand person and, uh, organization or you know, a thousand developers that you're, uh, serving, but it means that there is a sort of stakeholder management or community involved in the usage of the different solutions and automations that you have in place to deliver your software code. The second aspect that I think is worthwhile to highlight in platform engineering is the sort of evolution of like, the creation of a PA platform, which I think a lot of traditional DevOps didn't necessarily have their development or their work tracked in a roadmap and in sort of this, this sort of more traditional de uh, development oriented workflow. So one thing that we're starting to see is, you know, these platform engineering teams, the way that they're set up is they'll have a product manager, they'll have a roadmap, they'll have plans that sort of mix, uh, development work, platform development work with operations work, right?
And that further extends the collaboration with security teams, networking teams, infrastructure teams. So I, I do think that there's a lot of, um, now like a, a home for DevOps oriented work that traditionally didn't really have that much of a home in traditional DevOps. So I will say that there's a lot that kind of got introduced with platform engineering, but I, I think it's a wonderful idea to look back at, you know, what does platform mean to you?
And like, what does it mean to build a platform? Because at the essence of it, that's what platform engineering teams are doing. Can, can I, can I jump in, um, on that?
Sure. I, I think one thing, and I think, um, Teresa said this earlier that, um, like c, like C NCF and CDF are focused on tools. I think that the number one difference between platform engineering and the way, like the approach of DevOps, the approach of SRE and all the rest, right?
Has been that it's workflow oriented as opposed to tools oriented. And I think if you start from the tools, you fail every single time, um, because you're look looking at a very specific slice of the, of the workflow, and you're not actually looking at the totality of what the, of what's trying to be accomplished. So I gotta jump in.
com, I have to say, anyone who tells you that DevOps is focused on tools doesn't know DevOps, right? To Patrick dubois or John Willis or Damon Edwards or any of the people who started the DevOps movement tools is always third, it's about culture, right? It's about culture, it's about people.
It's the tools. Tools are interchangeable today. Today it's Jenkins, tomorrow it's spinnaker to the next day, it's something else.
But DevOps isn't about if, if you, if you are focusing that DevOps is tools, you got it wrong. So I, I want to, what I say there is that what you said is that a focus on culture, but I said is work workflow. And I think workflow is a product.
Culture is not a product. You cannot sell culture. Um, and so culture is an attribute of leadership, right?
And leadership actually has to actually do that, right? And so what you've pointed out is that leadership is failing at creating a culture. Um, but what they're, and what they're doing is empowering a social builder, Believe DevOps isn't working.
I, I assume you're assuming DevOps doesn't work, and it must be a failure of leadership and culture. I, I, I disagree with that. Um, if that's the case, Then I think if you're gonna Look at developer, Yeah, excuse me.
Uh, I would say that if that's the case, right? Then you'd look at things like the DX surveys and all the rest, the MPS scores of engineering organizations, right? There'd be significantly higher if it was working, right?
So all like, let's, let's forget DevOps, forget everything else, right? Let's just take from, uh, from a factual standpoint, how do engineering organizations feel today, right? And they feel disempowered.
They feel like they can't get their work done, and they feel that, um, that the workflow is broken, right? So now we can, we can say that there's like, doesn't really matter 'cause we can just go back to first principles. It doesn't really matter what, um, how we got there, right?
We have a problem. So from first principles, right? Like we can split it apart into three pieces, tools, technology or tools and technology, culture and, uh, workflows and, and the product of the said thing, right?
And we can look at each of those independently, right? And we can say how, how, how are they, how are they doing? Right?
Um, from we know that there is no workflow, right? We can look at the, the, the engineering teams are basically saying there's no workflow, right? If you look at the surveys that like that come out today, then you look at the tools, they like the tools, they're just complicated and they'll fall in the middle on culture, right?
And so, like all three of those today have some deficiency or some major deficiency. So I'm not saying DevOps is failing. I'm saying that like in totality, right?
Like it's not actually producing on either side of it. So Andrew, let me ask you a question. You are looking at today's surveys.
Let's go back before there was a DevOps. Do you think it was Nirvana and everyone was happy? Do you think it was bad?
Bad? I'm not saying 12 years ago. I'm not saying, oh, I, I don't know if it matters what 12 years ago looked like.
It only matters what today is, right? Because it's like, the question is How might we, well, you know, there's an old saying, when you get a little older, you'll learn this. Those people who don't learn history, you're destined to repeat it.
Oh, and I think it's learn. And what I telling you, I've been in this game for 30 years, and when you go back 25 or 30 years ago, there weren't a lot of happy campers. There were a lot of burnt, they're all a lot of burnt out people.
And the, and the, the, the banging between developers and operations and, and testers and security was pretty bad. Things have gotten better. The, were they perfect?
Are they perfect? Will platform engineering make them perfect? No, they're never gonna be perfect.
It's the nature of the beast. Oh, I think that's totally true. I think that the, the one thing that changed, right?
Because like, um, the one thing that's changed, right, is if you look at the current set of talent coming up through the industry, they've never seen anything but a cloud native world. And so that shifts the perspective of what they expect and how they expect the tool chains to work, right? And how they expect culture to be and how they expect, right?
And so if we, we can look back and say like, historically, yes, it was not great, but we also have to look at like, again, from first principles, like what does the current set of talent in the industry look like, right? What do they, what do they want? How, how have they expressed?
How are they expressing their needs? And if you then you project out five years, right? Like, what do they want is not the world.
Like, 'cause they've, they've seen enough of what's here today that they're saying, you know, I'm 25, I've never seen anything besides AWS and now I'm a tech lead. I'm getting, you know, my career path is the X. And they're saying like, look, I need a different set of tools.
I need a different way of operating. Um, I'm not saying platform engineering is nirvana. All I'm saying is that, uh, that the, that what is there today doesn't work for the current set of talent in the, in the industry and coming up through the industry.
And they're basically saying they're rejecting it. So I'm gonna jump to Nima 'cause I've seen you nodding your head on quite a few points. Um, speaking of companies, he listed yours, so why don't you kind of weigh in a little bit and give Andrew and, and Alan a chance to kinda breathe for a second.
Yeah, definitely. Well, I mean, very interesting conversation so far. And I think, you know, when I look at DevOps and the evolution to platform engineering, I think for me at least, things have changed are that, you know, practices of deploying to production are actually increasingly becoming more complex.
And if you look at, um, you know, deployments, I think, you know, there are, or when you look at DevOps engineering or platform engineering, you have to look at the capabilities that you want to kind of deliver to your, um, to your end users. And I think it's becoming increasingly more complex to think about the capabilities that are available or the requirements that your developers have, right? There was a point in time where the only requirement for deploying to production was that you actually find a server, you drop your binaries there, and then you kind of open the HGTP portfolio, the world to access your application.
Things have changed quite a bit. Right? Now you have to deploy to cloud, you have to look at continuous delivery, you have to look at running tests, you have to think about security, secret management, identity access, you know, load balancers, DNS servers.
So there's a lot more that you need to think about. And I think DevOps engineering was actually giving you practices and patterns that would solve it. But one of the things that I think we, we are seeing now is that there is a lot more tools now that can act, that can give you the requirements that you have that can actually provide you with the set of capabilities that you require.
So I kind agree with what Tiffany said earlier, that, you know, platform engineering is created to solve for this scale. You know, how many engineers you want to support, how many applications you want to support, and how many users you want to support. But more importantly, how you can actually provide consistency for all your application developers to actually do the same thing over and over with less deviation across the board.
And how you can actually make it simpler for your application developers to think about, you know, deploying their applications, how can you reduce the number of, um, you know, requirements that they need to address and provide consistency and reliability, right? So if you start thinking about DevOps engineering in the context of capabilities that you want to provide, and then the tooling that you want to support to provide those capabilities, and then to kind of create the culture and create the set of practices so that as your application developers change teams and, you know, move from one side of organization to the, to another side of organization, they actually have to deal less with, um, you know, the new set of tooling, the new set of overhead. I think that's the purpose of platform engineering.
So when we look at platform engineering, at least in the context of conversation that I have with AWS customers, it's about creating that consistency and it's about reducing choice, um, and, you know, giving you the right wiring, uh, for the set of tooling that you have so that eventually you can bring, bring that scale and consistency to your application developers, right? Um, I think it's important to think about consistency when we talk about platform engineering. The whole effort of engineering is to make sure that we have consistent, reliable and secure practices over and over available to application developers.
I'll, I'll make you pause there, but I, I'd like to hear whatever. No, I, I agree with you. The only point I would take NEMA is I, so I personally was never a big believer in the term DevOps engineer.
I don't, I didn't think that was a real job or a real function. I do think a platform engineer is what that role should be, right? Making that platform totally.
I think we have CICD architects, engineers, if you will. Um, but I think at the end of the day when we talk about this, it's about how do we let the developers work faster, better, more quality, and more in concert with ops and those ops or platform engineers or something, what, whatever you're gonna call 'em today or yesterday or tomorrow, it it that, that it has to be a better connection, a better fit where people's, you wanna call it workflow processes are more defined and, and so it allows 'em to go faster, better. And that really is what we're, we're after here.
I think. I think one thing that we also need to be careful about is that, you know, um, if you look at the CNCF landscape, and this goes back to what Andrew also said initially, there used to be a point in time where you could deploy Jenkins or you could deploy a spinnaker for your application developers. And they pretty much had everything they needed in order to deploy to production, right?
Spinnaker did a particularly good job in, you know, creating that developer workflows and having like an all-inclusive tool that you could give to your application developers and kind of define their practices. It, now, if you look at the CNCF landscape, there's like 370 different projects and each one of those projects only addresses a subset of the requirements or the capabilities that developers need in order to deploy to production, right? So when we think about platform engineering, it's a matter of figuring out first of all, which one of those 370 you want to to choose and how you want to compose those tools with one another to eventually bring the practices closer to what they used to get with something like spinnaker, obviously there's more to it, right?
But spinnaker did a lot of stuff at one point, and, you know, a lot of the customers that I talked to at AWS are the ones who, you know, were on a spinnaker or use spinnaker for a long time, and now they're in the process of modernizing their platform, but they need to rebuild that as spinnaker experience with these 370 different tools that are available to them. So the engineering aspect is deciding about choice, is deciding about composability, is deciding about the capabilities that they want expose, and the engineering aspect is them putting them together for, for the cohesive experience to become available to the application developers. So since we've mentioned Spinnaker, um, and I talked about this before we went online, uh, Andrew had a really nice, uh, LinkedIn post the other day about spinnaker.
So when NEMA talks about how, you know, it used to do one thing and now you have to really like rethink your processes. Andrew, what, like, what are your takes on this? Because I know you've got some, some opinions.
I think that Spinnaker was, so, I think Spinnaker is built for an era of individual machines, um, and it's been adapted for cloud native workflows. Um, you can see it in sort of how it's been built. I think it fails on a couple dimensions.
One is manageability from, like, you need a team to manage it and set it up, but like, like every single thread, right? If you go into spinner, right? If you go into spinner or Slack is just like, how, how do I set this up and how do I upgrade this?
Right? Um, that's like one big part of it. And I think the other part is what Nima touched on is that the composability of it is low.
You have to be a developer to compose on top of it. Um, there's no way to squat new backends into it without actually being a, almost a full blown developer. Um, and so that I think limits the ability for it to stay as a central orchestrator.
Um, I think what it has done exceedingly well, and I think the most underrated, um, blog post probably in the last five years in delivery is the managed delivery blog post from Spinnaker. Um, that entire post is, in my opinion, like probably what the next three to five years of c of CD should look like for teams. But it is very, very, it flies under the radar.
Um, but that post, it's like, I think the website is managed delivery, literally managed do delivery outlines exactly the pattern, in my opinion, that people should be looking at. Um, it flies under the radar and it's not, it, it requires a lot of leadership buy-in to get started, I would say, because it is going to separate responsibilities in a way that people are not used to. Um, but if you do it, it actually things flow way better from what we've heard.
Um, just like talking to people that have adopted the managed delivery pattern. Um, but it is flies under the radar. I don't think they did enough to publish it and like, actually push on that.
If I had to say one thing to c ncf F like, or CDF, like that workflow is substantially better than everything else Out there. That's like we should do. com or Cloud native now then.
Yes, Andrew, if you want to take that up, I'm giving invitation. We'll put it on cloud native. Go ahead, Lori.
Uh, so Didi, as person on the spinnaker TOC and the CDF, uh, board chair, like, why, why are we missing, why are we missing this? Why are, why is this the best kept secret? Um, you know, what, what's your take on that?
Like, how, how did we deviate from something that could be so big? Or how do we then push this forward and really kind of shine a light like Andrew said, that we should be doing? I, You know, I've heard a lot of wonderful things today.
Uh, let me just say that first, I think the contributions of everyone has has been really, really, this is a great topic. We should extend this, do more shows around this topic. 'cause there's so much to unpack here.
Um, and I think that, that, that's one of the core challenges because even in the managed delivery scope, you're still saying, Hey, there's a group of people who have to understand how to code and, and use this tooling to accomplish a thing. So that, that doesn't shift into Andrew's point about needing a team to run Spinnaker. I I completely understand that.
It's a, it's a very flexible tool. Um, and it's that flexibility that gets, you know, folks in trouble. Uh, and so, you know, we in the spirit community, uh, recognize this and are working to make the lower the bar to entry.
So that's one of the things that we're actively working on. But I, I, I will call out that the thing that we're, I'm not hearing about is the other people who are moving into the space of needing to use these tools like data scientists, um, who need to be serviced and don't have this depth of understanding on all of the pieces. Is this the same thing that's happening to the developers?
And so we are talking about all of the pieces. Like we, we've mentioned that there's a software developer lifecycle workflow that we need to account for, and that those are gonna be different and different people have different needs in that space. Managed delivery gives you that flexibility to kind of move around in that space.
But you still need someone to be the expert to kind of guide that proc to practice and then map out very, very clear templates that people can use and say, okay, this is the way you get this to production. 'cause most of the, the developers that we're actually talking about, they, they having them having the need for them to learn all of the different pieces of the platform and understand how they come together and understand the DNS and understand all of the configuration, that's a lot of challenge for a new developer coming out of college who's never seen these things. It's a lot of challenge for the guy who's been working on one thing for 25 years that's just like, he is focused in on it, on a product or a feature.
And then it's like, Hey, stop, learn all of this new stuff for something you're gonna use once or twice. 'cause once it's set up, it should just work. And that's one of the things I will point out about spinnaker is that once you get it up and it's just going, it just works.
And so, um, I I will, I will point out that managed delivery actually, uh, discourages the use of templates and encourages exactly's point. That's my point. It's that's my point.
Yeah. It it's just about requirements, right? Right.
It's just saying like, define requirements for it, not, not templates to, you're not supposed to have to go understand DNS to use managed delivery. You're supposed to be able to just deploy with your requirements of my application requires X, Y, and Z at the app level. Um, right.
But coming from the opposite direction, if you are a CEO and you're going, Hey, I want everything stable, I wanna be sure that people are following the best practices. You, you want something that, you know, isn't just like, Hey, giving your set of requirements, like everybody's gonna do this thing, is the mindset, at least in the conversations that I'm having in the community with leaders that like, no, how do I make sure that, you know, there's DevSecOps, there's all these other pieces that need to be checked off. I need a way to ensure that people are going through all of the steps all the time.
And, you know, you're, you're now mixing the, the managed delivery aspect, and this is how it's suggested to versus how leaders want their businesses to run. And this is the crossroad why this conversation is so interesting. Right.
No, totally. I I mean, I think that the, my dick is that this is where I go back to sort of like what you look at. Uh, I I tend to look at it as, okay, there's a leaders that you're selling to today, and then there is the people that have only ever grown up in cloud Native.
And if you come from a world of where you look at something like Kube, right? Like the, the, the irony right, is under the hood, who Kube is not implemented as a checklist, it's a convergence system, right? And so like all of the tech right, that's there, the tech that's there, that works the way people think it works, doesn't actually do the thing they think it does.
Yeah. So guys, we're in the middle of a research thing here at, at Techstrong on a, a large project called DevOps, uh, DevOps next, right? And we're looking at kind of what's next in DevOps.
12, 13 years in. And it, it's based on surveys of people. It's based on interviews and it, but it's also based on what people are reading on our sites, cloud Native DevOps, security Boulevard.
And here's an interesting thing, and, and Android, it goes to what you were just talking about, about for today versus tomorrow and and beyond. We all think cloud native is dominant and cloud native is dominant on new applications. Like if you have a greenfield, you are, you are building it in a cloud native environment.
But that doesn't mean that there's not a, I don't want to curse a, a bunch of of work, a bunch of applications, a bunch of infrastructure out there on AWS and the others that are not cloud native that we can't, you know, maybe over time they'll be converted, maybe not, right? There's, but there's a lot of stuff that's not cloud native. Even something as like DevSecOps.
'cause I come from a security background, I think, of course everyone is, you know, looking at DevSecOps and moving security left and and whatnot. But the fact of the matter is, a relatively small amount of enterprises have kind of really adopted DevSecOps. You know, we tend to live in a bubble and, and people on this panel as well, where, you know, we're always looking at the latest and greatest we're the, the classic early adopters of, of new technology.
But when you look at that mainstream, right? And the classic models of crossing the chasm, 35% of the mainstream is a little earlier than there's 35% later adopters, and then 15 or 20% laggards or whatever it is. I think it's important to remember there's still a crap load of people who used Jenkins, right?
The last CDF survey, 40% I think was the number of people doing C-D-C-C-I-C-D used Jenkins. And, and I'm not disparaging Jenkins by the way, I'm just saying that those are the numbers. So it's good to say what we want it to be and what it should be, but we also have to recognize what, what our listeners, what our watchers here are dealing with.
A lot of them, you know, say, I wish I could do cloud native, but a lot of 'em say, I wish I could implement some of the stuff, you know, that we're, we're talking about here. But a lot of them can't, unfortunately, can't, unfortunately, because they, they're stuck in legacy land that's not Lego land. But, um, so I think, you know, we need a pack.
I'm sorry, Dan. Yeah. So I think one of the things that I, I, I get this question a lot, you know, working with a lot of AWS customers, there's a lot of legacy applications that run, not necessarily on Kubernetes, but other parts of a Ws, there's a lot of applications on premise that, that customers use.
Um, so one of the things that is important to, to kind of remember is that, you know, there is a separation between how you manage your applications and how you run your applications. And I think a lot of the conversations that we have, at least recently with a lot of the customers is that, okay, if you wanna go towards modernizing your DevOps practices and your platform engineering, you can have the management piece be modernized and still you can create the ability for this modernized platform to manage your legacy application, right? It doesn't contradict that, you know, you have a stuff running on bare metal, right?
It doesn't contradict that there are parts of your application that have Jenkins and, you know, kind of execute the workflows for them. Um, it is important to recognize this part of the modern modernization work that you wanna put in place. There needs to be some piecemealing work that, um, you know, goes into play.
And part of that piecemealing is going to involve, you know, revamping your platform and having your platform kind of, um, you know, uh, cater to the legacy application as well. So I, I don't necessarily think that people need to think that they're stuck with their legacy application only because they're using legacy tooling. No, there is hope, there is a pathway to migrate to more modern stuff.
It's going to take a little longer, it's going to be more, um, you know, there's gonna be more challenges and it's gonna require more effort. But, you know, the path to migration is there. And I think that's an important message to get out and let people know.
Absolutely. Absolutely. Guys, this was a lively discussion, but we're coming up on time.
Tiffany, I feel like we haven't heard enough from you though. I'm sorry to pick on you, but what do you think, ha, having listened to all this? Any thoughts?
Yeah, I'd love to touch back on the managed delivery component because I think Autodesk and that ecosystem kind of sits in between level one, level two and level three, given that there's just been so much history at Autodesk with, you know, initially having like executables things that you download on the desktop and then now like moving towards a more cloud ecosystem. And a lot of that has changed, and we see so many different kinds of workloads, like in my day to day, see so many different kinds of workloads. And one thing I've realized is that while you can have those ideas of modernization and like, oh, you know, this would be the ideal.
A lot of times you have to be okay with sitting in the middle of all of that because it's work in progress. Like, we have a ton of things that are configured as code, right? They're not necessarily templates, they're not necessarily self-service.
And the way that you get your, uh, your code into production is, your applications into production is through configuration as code. And it's a lot of configuration and it's custom configuration. And that's not even including the fact that you might have a complex workload, right?
And that's something that is really helpful for people to like note, especially as they're developing platforms and engineering the solution is like, how are you gonna bring the rest of your community with you? Um, and that's something that, um, a lot of people forget as well. Like, you know, we get so busy, we have the frameworks for the platform engineering, then we forget the culture piece of it, right?
So how do you throw in the culture piece of it back in and ensure that developers have a good sense of like, where this is going and is it sustainable and, and all the things related to that. So I, I just wanna sort of leave the, the open-ended question of, of that, because I, I think a lot of support work developer relations type work is not really mentioned a lot in the conversation around DevOps, but it is very integral. Like, who, who do you have in your organization that's going to nurture the community and ensure that, you know, everybody's included when, when it comes to automating different workflows.
So just something I'd like to, to leave everybody with here. Thank you. Thanks, Tiffany.
Andrew, your closing thoughts? Um, my closing thoughts are, I think it is an exciting time to be working in the space of platforms right now. Um, I think that there's, that the amount of change just in the last 18 months is so high that it's like, it's really nice to see people actually caring about the space and realizing that it can be a force multiplier for organizations as opposed to cost centers, which is great to see.
Also, Andrew, we didn't catch your company's name, if you wouldn't mind. Oh, if people wanna go check it, Uh, prana. Prana.
Perfect. I just wanna make sure people can get there. Nema, I don't think you have to spell out AWS but your closing thoughts.
Um, yeah, I agree with, um, with, um, what everyone else said. I think this is super exciting times for platform engineering. I think there is, um, there is a lot of, um, new, um, technology that is coming out on a daily basis.
There is a lot of interesting new challenges that you see. Um, you know, companies like crx, uh, Upbound, um, you know, you naming the Acuity, they're solving at different levels of the platform stack. And I think, you know, as these new solutions come out, it becomes more and more interesting for people to wanna compose this together and build that platform.
So I think we're gonna be constantly on the lookout moving forward and deciding about what are the tools that solving, improving that, that productivity by smaller percentage. And, but those smaller per percentages at a scale, they come at huge value. So, um, engineers are gonna be on, on phase.
They're gonna be looking out for these new technologies and pick up things so that they can improve the productivity of their application developers, certainly exciting times. Excellent. Thank you to dc You wanna give us some closing thoughts?
Yes. I, I just wanna say that, you know, a lot of this conversation centers around cloud and I, I, it brings me back to my original conversations as I was beginning to join the CDF with Ericsson and some of the things that they needed to deploy to just aren't cloud, right? And you, you have this whole space of other things that need to be accounted for and these platforms as we move forward.
And I think that's what the CDF is thinking of, like everything else from the tool perspective and how we connect this to make better platforms. Um, I'm, I'm gonna give a, a, a plug for something that NEMA is working on, which is the Canoe project. I, I encourage folks to check that out, just the thought process behind that.
io and, um, it, it is, it is building platforms from tools that you, that you already have. And I think that's a, a great way to approach it and extend it beyond just this conversation of cloud. But how do we get that to, like our, our data scientists?
How do we make this available to all of the other things that you might need tole to as well? Excellent. org Is that it?
Io Do io. Excuse me. Okay.
Check that out. Lori, take the last word. Thanks Alan.
And again, thank you so much for this partnership with Techstrong. I think one of the things that, uh, that I love about this show, and I love about the CDF, is this idea of community. And so I highly encourage you to join our Slack channel and get involved in the conversation.
You can have your own hot take conversation and really kind of dig into why people think the way they do. Why are they doing business the way they're doing business, why this is such an important topic, and how it can really level up your team and your skillset. And, you know, it's all about finding the solutions that work best for your company and being surrounded by individuals that can help you get there and have these kinds of dialogues, which help you think more about what you're doing, how you're doing it, and maybe you go hard left instead of what you thought was a hard right.
You know? And so, again, the Continuous Delivery Foundation, it's a great place to have these sorts of conversations. And so, Alan, thanks to the panelists.
This was so much fun. I look forward to maybe coming back in a few months to see what's changed, what new innovations you guys are talking about, and, um, and bringing these topics again to light. Absolutely.
Hopefully not a few months. You can visit it before that. Speaking of CDF though, just a quick plug.
Open Source Summit's coming up in Seattle, uh, soon, next week. Yes. CDF is doing the, is doing things there.
Yeah. So we'll have CD Con, uh, we'll be in a room. It's two days on, um, Wednesday and Thursday, I believe.
Uh, we'll have a state of the Union. We'll have panels. We have lots of talks lined up.
We'll be there with swag in the back of the room. Lots of cool stuff to give away and lots of cool things, uh, on the agenda. Cool.
Wanted to make sure we hit that. Thank you guys. Thank you all, Andrew.
We hope your child feels better. Thank you. We, we, I think a lot of us have been through that kids are resilient, but it just, it's, you know, watching them be sick is not easy.
Um, but to all of you, thank you so much. This was a really great, lively discussion. I have no opinions on this at all, so I apologize.
But, um, until our next show at CD Pipeline, keep up what we're doing. And until then, everyone be well. Bye-Bye.
In this next episode, another video series, it's our DevOps Unbound series where we discuss all things DevOps. And in this one, we actually have another tricentis person. Martin Klaus, uh, VP of Product Marketing at Tricentis joins us and we discuss the progress.
So the, the progress that software testing has made during the rise in adoptions of DevOps and Cloud Native. And I should mention, we recorded this live in Paris at CubeCon. Hey everyone.
Alan Humel. I'm back here live. We're back here, live at Q Con.
This is by far the busiest show floor I've seen in any Q con. I know there's 13,000 people and I think they're all right here. Yeah.
Um, luckily the magic of technology, you're hearing us and seeing us, I hope. And because if you will hear the d of the background noise here is ridiculous. I'm really happy.
We're gonna be doing a little bit something special here. Right now. We're gonna be doing a DevOps Unbound live kind of panel live at CubeCon.
We've got our very special VIP guest, Martin Cost, who evidently when he travels at events, brings his own security and, uh, Mihi Mihi and, uh, hash. These are your friends. Mitch.
We're thanks to keeping us safe. We appreciate it. Thank you, gentlemen.
We appreciate it. You're good guys. I don't know, I guess Martin's a high visibility kind of target or something here, huh?
I don't know what you're into, Martin, but I'm glad you're, you've got security. Something outta the blacklist or Something. You guys are too funny.
But, um, anyway, so this is Martin Klaus from Tricentis. If you've watched any DevOps Unbound episodes, you might have seen Martin Aren't a few of them, but you know, it's funny, at Zoom you only see people from here up. He's actually a pretty tall guy.
Um, speaking of tall guys, to my right here is our CTO at Techstrong and Principal Research Analyst, Mitch Ashley. Mitch, thanks for being here. Always, always.
And, uh, we're here. So, DevOps Unbound, look, we always discuss everything under the sun on DevOps Unbound. But Martin, I wanted to focus today's talk a little bit on what's different about testing and continuous testing in a cloud native environment versus any other environment.
Yeah. So first of all, uh, Alan, Mitch, thanks for having me. It's great to finally meet you in person after many, many years.
Yeah, it is. Yeah. Uh, and it's unbelievable, the energy, the vibe, the community of con as you mentioned, 13, I think it's actually more than 15,000 people are here.
Yeah. This place is crazy. It's unbelievable.
If you have not been to Q Con, you definitely to come here in person and see for yourself. But coming back to your question, what's different? So I've been in cloud native for a long time.
I've worked at Red Hat. 9. And, and so I would say if you look back over the last couple years, a lot of things have changed because, uh, one of their main objectives of DevOps was to, to bridge the gap between Devon Ops and to move, uh, you know, applications in production, value in production much faster, deliver more value to business much more quickly than in a traditional waterfall or even an agile model.
And so what happens is when you're trying to move faster and you change your process to work more efficiently, to work in small increments, then the application architecture evolves as well. Right? We have moved from, you know, monolithic big web applications to microservices that you can update and scale out much more efficiently.
Data has evolved from data rest to data in motion. And streaming of events has become one way for data and applications to communicate with another. And so, uh, if you think through that, then you also have to think about how does that impact, uh, testing and test automation?
And the whole notion of quality engineering becomes a lot more important. 'cause you have to think about quality from an architecture standpoint. You have to think about quality from an end user standpoint and, and the experiences to deliver.
But you also have to think about how can you ensure quality through the development process as it relates to functional requirements and relates to business requirements as it relates to performance requirements. And a lot of companies are also dealing with security and compliance and governance. So all these things have to be considered.
And, uh, it cannot be solved by tools alone. You have to think about the process as well. And, uh, most important, I would say is first mindset and not just, you know, move things in production and see, see if it sticks.
Um, but be more thoughtful about how you're building applications, how you deliver it, and ultimately what is the value delivering to our end users. Yeah, I I'm curious listening to your thoughts on that. You know, thinking about the people that we've interviewed and just a few of them today already, you know, it's OpenShift Red Hat folks, it's ARM processor and getting more applications on, on that platform.
Um, it, it, it's, um, you know, cloud native application companies, it's object storage, the number of variables. I mean, there's always been a large number of variables Yeah. To test for environments.
It seems like that's even bigger. I mean, you know, maybe exponentially more complex Yeah. In this cloud native environment.
'cause there's so many different platform. I mean, ai, you add all that to it. Yeah, I, I agree.
I think if you just walk around the SHO flight here, you'll be blown away by how many different use cases and features and capabilities that are enabled on the community platform. I think one other aspect that's really important to think about is, you know, develop or testing is everybody's responsibility or qualities of its responsibility. Not just, uh, the traditional QA folks, uh, it's developers, it's project managers, it's release engineers, it's SREs and everybody else that's involved in it.
But one key difference, uh, oftentimes is, and this is something that I hear a lot from, you know, my quality engineering counterparts at, you know, not just adjusting companies, but the enterprise. That it's not just about the happy path, you know, that you envision as a developer that your users go through. Uh, quality engineering is all about, you know, finding out what are the edge cases where things might break.
What are the environments where you, you run into a gotcha type situation, and how do we prevent that from happening? Because ultimately, uh, end users all have different environments, different browsers they log into through mobile devices for different network configurations. Uh, they may have multiple applications running, and inevitably somebody's going to use the application in Wave it was not intended or designed to deal with.
And, and so that's ultimately causing quality shares. And so that's really, I think what quality engineering to be about, is to figure out how can we maximize the footprint of all the things that we're exposing the application to the identify those weak points that we need to prevent from happening in the first place. Martin, one of the trends that I see at cloud native Con con already is the, the move to platforms, right?
And, and I think it's a maturation phase of, you know, we're doing this, Mitch is heading up this report we're doing called DevOps Next, where we're looking at what's next in, in the gamut of DevOps. Yeah. Right to left, left to right, left to right, you know, the whole thing.
And one of the trends is, Is Instead of cobbling together, you got some, I feel like we're on the airplane, you know, I feel like I'm at the airport. Yeah, I'm ready. I gotta go board.
See you later. You're you're missing your flight. Yeah, but the think I left my wallet at the TSA booth.
That's right. Um, but one of the trends is getting away from point solutions that are cobbled together to platforms and almost like the Russian nested dolls, platforms of platforms. So you can have a continuous testing platform like a tricentis, and that has a complete suite of tests optimized for a cloud native environment for what you're doing.
And that has to fit into a larger cloud native platform. You know, that takes up my whole CICD, my whole software supply chain type of environment. What's Tricentis doing?
Going to expand that testing platform, but also to fit into that larger cloud native? Yeah, I think that the notion of PLATFORMIZATION is, is one of the hottest industry right now. Now you hear about platform engineering, you hear about development platforms, you hear about, uh, quality platforms, and the main driver for the adoption, uh, or the growth of these platforms in history is really like, what can we do to help help developers or testers and project teams stay in a flow?
Because there's so many things you have to think about. There's so many distractions. There's so many sort of other tasks we have to do during the day.
And to stay focused on a particular pool request or a particular project or a particular sort of feature requirement, it's, it's very hard, uh, if you think about all the meetings and disruptions that you're gonna deal with every single day. And platforms can help with that to help you simplify and automate a lot of things so that there's less, uh, cobbling together that you have to do, uh, on, on your own. And one thing that is really important, uh, I think also from a Zen standpoint is, uh, reusability and how can we enable more use cases with quality platforms?
And, and, and one thing that we see a lot with our customers is that there are not just applications to build in house in the enterprise. There are applications that, that you or SA applications to configure and deploy or enhance, uh, or an application to just use. So you'll see, we see the whole gamut of applications that you deploy and configure, uh, that you use across the enterprise, but then also applications that you're extending and building yourself, and how can you deliver an end to end quality automation platform that supports all different use cases between enterprise IT back office applications like Oracle and v uh, business applications like Salesforce and ServiceNow and many others, as well as the custom applications that you use internally, but they can also be client facing, right?
And what we found is that a lot of customers are looking for ways to, uh, standardize process through a quality engineering framework, but they're also looking to standardize tools and platforms, so that enable quality engineers across many different teams to work together with their developing counterparts to release applications faster. And so that's kinda like what we're trying to do to really focus on usability and the end user experience, but also make it easy for people to get started with functional automation, but then expand into, you know, data testing, for example, or load testing, mobile testing and other things, uh, that, uh, they may need to do for the particular application that they're trying to release. Really makes the case platforms aren't just for infrastructure.
Yes. No, that's part of it. But it's platforms up the stack and Well, it's horizontally horizonal.
Exactly. It's the key To it. And like I said, it, it's like that Russian nested dolls thing that's platforms within platforms and, but again, For Dune, you gotta make it a dune plans within plans, Spirals within spirals, Yeah.
Or think about this as layers, right? Like the, the networking layers of, you know, L one through L seven might be one analogy to think about what you doing on the infrastructure layer, what you're doing at the application layer, at the testing layer, and so forth. Well, at the end of the day, the spice must flow.
Let's see. Sleeper must awaken too, but, so can I ask the AI question? We haven't talked about Ai No, it's, it's enough time.
Go ahead. We have, we have an upcoming live session on testing AI in your applications. I'm curious your thoughts, and I wish I had the, the data on it.
We'll, we'll, we'll get that out to everybody. What are your thoughts about when you incorporate ai AI into your apps? There's models, there's data, there's training, they kinda have their own flows or, you know, even more so than just a database or data source.
How do you think about testing in a, in a cloud native world that has AI part of it? Yeah, that's a great question. I think that's answer That in five seconds.
The whole industry is sort of, uh, thinking about that right now. Because on the one hand, today, for example, we saw many great use cases for AI models and for them production and, uh, you know, using LLMs to summarize, uh, a live fixture of what was being seen. And, and so also we're seeing, you know, the use of AI from a co-generation standpoint, right?
And there was a recent article from, you know, Joe Bonai who mentioned that, you know, we've shifted the problem, you know, from development to QA and what used to be, you know, three developers, one qa, it's now one developer and three QA because, uh, developers can now generate so much more code using AI tools. And now that puts the burden on the, on the testers to verify, you know, the increase in credential security, uh, flaws are being introduced, uh, if the code is not being tested and validated, but generated from some random source. So that's one aspect.
But I think the bigger question in industry right now is how do we test the validity of the results of an AI model? And if the summaries and, uh, all the things that an LM can generate are, uh, meaningful and they're not, uh, they're free of hallucinations and things of that nature, I think that's a great use case for exploratory testing. Um, I think there's also an opportunity to actually use other LMS to test the output, you know, from LMS and see if there's a consensus around among LMS on the results.
But at the end of the day, um, you know, uh, you still need a human in the loop. Uh, you cannot, we're not at this point yet where the human is completely eliminated from the FS cycle. And as the, the technology matures, I'm sure there's gonna be more opportunity for automation to test ai.
But for now, I would say we're still very much in sort of the, the good old, you know, you know, exploratory testing, being able trace back to the data, you know, how the A elements came up with certain results. But, uh, you know, that is still so like the big, the big problem for administrative crack. Makes sense.
No doubt. I mean, we can stay here and talk cloud native and AI and q testing. Well, everyone else here is q testing.
Actually, AI was the star of the keynotes today too. Yeah, that's what else we heard. Anyway.
Hey, Martin, I want to thank you for stopping by. I can't believe you came all the way to Paris just to do it Cloud media Yeah. For this one session.
This is great DevOps unbound thing with us. Commit. That was nice of you.
That's commitment. Yep. But seriously, thanks to you and Trace.
Thanks having me. This as always, we're gonna be back to our regular schedule of DevOps Unbound, I guess, when we get back in another week or two. And, but until then, we'll be here live all week, covering what's going on at CubeCon.
Many thanks to Martin Klaus and Chiantis Mitchell. Ashley and Alan Shimmel. You're watching Tex Drunk tv.
Next up, we have another video show. And this time it's our tech strong women and host, Jody Ashley and Tracy Reagan have one of my favorite people on Caroline Wong, who's chief Strategy officer at Cobalt, and they do a deep dive on cybersecurity and beyond check out tech strong women. Hi everybody.
Thanks for joining Us for our, for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech. I'm Jody Ashley, executive producer at Techstrong, here with my co-host, Tracy Reagan, creator, and CEO of Deploy Hub and Linux Foundation Enthusiast Peak four. I Today's guest, I wanna give you a quick update about what's happening here at Textron.
Be sure to register for Textron Con 2024. It's happening on April 3rd, so you can still get in there if you wanna, if you wanna attend. Um, also, we are launching a really cool and exciting virtual event called the Artificially Intelligent Enterprise on May 21st.
It's going to be a 24 hour global event, so you won't wanna miss out. com and register for all of our events. And we'd love sponsors.
We love speakers. So keep your eyes open and you'll be able to sign up to do that stuff. And be sure to tune into Techstrong TV every day for amazing content shows and interviews.
Hey, Tracy, what's on your mind today? Well, I think a 24 hour kind of follow the Sun conference on AI is pretty interesting. I know it's gonna be fun.
I'm looking forward to it. Absolutely. So, you know, today I wanna talk about, I often talk about Jenkins, but I'm gonna talk about it again because it continues to be a prime tool that companies, enterprises around the world have used.
And this happened in late January. Um, about 45,000 Jenkins instances were exposed to an online vulnerability, uh, that allowed them to get remote code execution, or depending on your, your security settings, basically gave you a, a access to the command line, and to be able to get access to certain, uh, files, 45,000, um, servers. We, uh, we, everybody has to stay diligent, right?
Um, and tools like Jenkins, while everybody works really, really hard to make sure they're secure, you never know when a vulnerability's gonna pop up like that. So, I just wanna put it out there. It was out, you, you might, uh, look for it.
It's, uh, it was published back in, uh, late January, and it really talks about the exposure and why it's important to fix it. So I'm putting it, put it out there for you Jenkins users, look to see if you have that particular version and if you have an issue. All right.
Thank you, Tracy. All right. I am so excited.
I've been trying to wrangle this lady for quite some time, but she is very busy. Um, our, our guest today is Caroline Wong. Caroline, tell us about yourself.
Thank you so much for having me. I am delighted to be with you two today. My name is Caroline Wong.
I'm the Chief Strategy Officer at Cobalt. We're an offensive security testing company. Um, I've been working in cybersecurity since 2005, starting off on security teams at eBay and Zynga.
Um, in 2011, I published a book called Security Metrics, A Beginner's Guide, uh, in 2022, that book was inaugurated into the cybersecurity Cannon Hall of Fame. Um, I teach courses on LinkedIn Learning, and I host a podcast called Humans of InfoSec. Very interesting.
And I know that you are passionate about, uh, teaching and talking about security and cybersecurity at work, uh, which is a really interesting topic because no matter how, how hard we all work to secure the supply chains to secure our environments, somebody can put an use their pet's name, which we probably all do for, for, for a, a password, and all of our hard work is gone. So why don't we talk, start today about talking about, you know, cybersecurity at work and, and how people should approach cyber, what we should know as we we do our daily work. Yeah, first I just have to say, Tracy, I love that you opened up today's session talking about a vulnerability in Jenkins.
This is something that I get really excited about because the thing about software is that it's vulnerable. And unless we're proactively security testing it, unless we're proactively installing fixes, the vulnerabilities are just sitting there waiting to be exploited. And I think that the thing, the, the main concept that I try to communicate in cybersecurity at work is simply that everyone's getting attacked all of the time.
All of our organizations are under attack right now. We're just all being attacked, you know, and if folks could understand this and understand that it's something that happens all the time, every single day, and not just sort of a random occurrence, or if you're doing something super important, or if you have some sort of super confidential restricted information, everyone's getting hacked all the time. And that being said, my sort of, first I would say there's really three things for most people to keep in mind.
And this is what I say. If I'm talking to my 8-year-old daughter, or my 7-year-old mother-in-Law thing number one, look out for phishing. And if something seems too good to be true, it very well might be.
And just take a screenshot and send it to me and I'll check it out. Um, but, but whether, whether or not you're my literal family member or not, you know, send it to someone you trust and just ask them to take a look at it. Um, and make sure that if there's an opportunity to verify it via some other route, for example, you know, you get a text message and it claims to be from a shipping company, go online, go to their real website, call them up and ask about it.
Um, so number one, we are all getting phished and social engineered all of the time. Uh, learn to expect it and learn how to, uh, question it. Thing number two, use multifactor authentication.
I'm not saying that it's okay for all of our passwords to be our dog's names, but if it were, and we had two factor authentication, authentication, then we'd be in such a better spot. Um, and these days, you know, that kind of thing is really so easily accessible. Um, so definitely for online banking, definitely for email, really for anything that you really care about, just turn on my multifactor authentication all the time.
Do you need to do it for Netflix? Maybe not. Do you wanna do it for Amazon?
Probably. Um, and then the third thing, and this is really geared toward sort of everyone, all of these tips are geared toward everyone. Update your software.
I know how annoying it is, and when it takes me 20, 30, 60 minutes of time where I am unable to access my laptop because Apple has released yet another OS update, by the way, is it just me? Or do they seem to be coming in really, really frequently? But you know what?
I don't care how frequently they come in, you gotta prioritize it, because hopefully, even if you don't prioritize it, your organizations, it security team is actually making it happen. But what's gonna happen if that's the case, is it's gonna be a Friday morning and you're gonna be on an important call, and all of a sudden your computer is just gonna start installing and updating, and then you're, and then you're, you know, it's gonna be really inconvenient. So just pick a time, you know, maybe it's the end of a workday.
Um, and, you know, you're about to go take a walk. You're about to make yourself a cup of tea. Just install the update, do it for your os, do it for your laptop, do it for your smartphone.
I really think that between those three things, if I could only tell folks three things, uh, those are really it. Um, but I will give a little plug for my cybersecurity at work course on LinkedIn learning. Mm-Hmm.
Um, if anyone's interested in viewing that course, uh, you can find me on LinkedIn and on my feed, I've actually got a featured post, uh, where you can watch that training, uh, at no cost to you, even if you don't have LinkedIn learning. Um, and one of the things that we did that was really fun was we did a couple of scenarios. Um, so we tried to make it fun.
We tried to make it engaging. Uh, I like to think that it is, uh, pretty engaging and pretty fun as far as cybersecurity training goes. I'm absolutely gonna go check that out.
Um, and you know who my husband is. So the two factor authentication thing is been a thing that I hate and drives me crazy, but somebody makes me do it. So it's attached to everything in our house already.
But getting younger people in their twenties and thirties, their twenties and thirties to update their computers is such a nightmare. Like, we have kids that are working and they have a max, and my daughter doesn't, how often she'll be like calling, like, I can't, my, I can't work today. And Mitch will be like, well, do you need to do some updates?
And, you know, it's six months old and you're like, so I have another question though. When you talk about, um, companies trying to hack and security breaches, you said that a lot of them sit there waiting for the moment. How much of that happens and how long, you know, how many people create stuff and it just sits there for three, four months waiting?
How long, how often, how common is that? So here's the fundamental problem, software and the internet. The power of software and the internet is connectivity.
The internet started out universities trying to share information with each other. We had atmospheric scientists trying to share large amounts of data. The internet was not built to support global electronic commerce.
It just wasn't. And so security is not inherent to software. Security is not inherent to any internet protocols.
In order for something to be secure, it has to be secured on purpose. And the best way to ensure something is secured is to test it, go after it with an attacker mindset, the offensive security mindset, test that software, find the vulnerabilities, fix the vulnerabilities. Um, it's really the only way.
And what happens is if you're not even looking mm-hmm. The vulnerabilities are just sitting there. If you are looking, then at least you know where some of it is, and you are in a position to address it if you choose to.
Now, there are trade-offs involved, right? Because security testing costs money and addressing security problems, cost resources and money. And this trade-off is where sort of the security complexity lies, Mm-Hmm.
Um, but on one hand it's actually simple, which is to say, do technical security testing, go and find those vulnerabilities, and then work with development teams to go and get it addressed. And that is part of the bigger problem, because we are finding vulnerabilities. Vulnerabilities are now being founded at, at a, uh, a rate that we are, are not used to.
Mm-Hmm. Because now we have vulnerability databases. We have tools that are sta scanning for vulnerabilities.
We're reporting them. Um, and you, you know, of course, Jody said I was gonna talk about SS I'll have to, I have to kick this one in. Um, if you don't have an SBO m you don't necessarily know the, uh, vulnerabilities of blast radius, and you don't know what the remediation step should be.
So I often, uh, talk about the, the future where we have a FEMA like response for vulnerabilities. Why don't have to wait if somebody's found one, get it, get it communicated. We lack collaboration in this area at a global level.
And I've spoke to some people that says, well, we don't want people to know where those vulnerabilities are, because then hackers will know it about it too. But the sooner we know about 'em, the sooner we can shut the door. Oh, they already know.
They already know. They already know. That's what I, and we don't, vulner Vulnerability database is public to everyone.
Everyone, You're a good person or a bad person, you know, it is equally accessible. And the bad person is probably more likely to be hunting around the vulnerability database to find out the ones that they want to go and attack. And the good person is the one trying to get software out, right?
They're the ones working and trying to get their software out. They're not thinking about looking at the vulnerability database every day. And if you don't, if you, if you don't know where those vulnerabilities are in your, in your, your software supply chain it from this, from a coding perspective, it's hard.
It's hard to get those fixes in. And then the remediation is not shared. So somehow the industry's gonna have to get to a thinking about this in, in a FEMA response.
Now, you talked about it, you, I think you talked about it, uh, um, you said two, two terms. One was the hacker's mindset and an offensive mindset. Why don't you talk a little, get get a little deeper into that so maybe we can better understand how to solve the cybersecurity problem?
Yeah. In my experience talking to hundreds, thousands of security and development practitioners throughout the year 2023, there was a really big theme which emerged. And the theme which emerged is everyone's experiencing layoffs and everyone's experiencing budget cuts.
And what does that mean for cybersecurity practices? It means there's simply less to go around whatever limited resources we had before to allocate towards managing different risks that's now smaller. And so I would like to put out the idea that when thinking about a cybersecurity program, you can think about two domains.
One which is defensive security controls, and one which is offensive security controls. Multifactor authentication is a perfect example of a defensive security control. One that I think is really important to do so is updating your software.
But an offensive approach says to your point, Tracy, about attack surface. Do I even know what my attack surface is? You know, am I aware of any sort of shadow domains, dangling domains?
You know, what's out there that actually belongs to me that I'm responsible for, that I may not be looking after? And once those assets are identified, security testing, whether that is scanning, that is manual penetration testing, taking a look at your organization's digital assets and considering what it looks like to an attacker. Um, and, and, and my thought is by doing this, organizations have an opportunity to focus their very limited resources on addressing the items that come up in that offensive security analysis.
Cobalt actually just published a report called the Off sec Shift Report. Uh, and it contains a bunch of data, um, from thousands of, uh, security and development, uh, practitioners, uh, that talk about how budgets are shifting and organizations are investing more in offensive security for exactly this reason. And, you know, this concept is new to me.
This a concept of offensive. I think most of the things that I think about are, are defensive, right? Beyond just knowing what digital assets you have to manage.
Is there other ways? You know, I think offense, I'm a hockey person, you know, we have a goalie, we have, you know, we have defensive players. Who are the players in that kind of, that offensive world?
Hockey Feels like the right analogy, very physical, you know, boom, boom, right? It's not subtle. Yeah.
We, we have forwards and we have our wingers and what are our forwards and wingers doing Right to go and score? What are they up to? I think, you know, you've got sort of a few classic categories of attackers.
You know, you've got sort of the really big scary ones, you know, nation states, um, but you've got others. You've got potentially, um, you know, competition, um, search, searching for intellectual property. Um, you've got your sort of typical, um, you know, spray it all type of scammers who are just looking to make a buck any possibly way they can.
Um, certainly ransomware, uh, is a big way in which people and organizations are being exploited. Um, and these days, the thing about being a hacker is that hacker tools and approaches are not that expensive. You can buy a password cracking system and, and the storage required for it for less than $50.
Um, it's just not that hard to do. The bar is just not that high, so it doesn't require a lot of money. If you've got an internet connection and some knowhow, um, then, then there's a lot of power, uh, on the attacker side.
Um, and I think as organizations, what we really need to do is we need to say, okay, what does our attack surface look like? What is our critical data, our critical systems that absolutely need to function? Let's do a bunch of security testing and let's make sure that the vulnerabilities that are found are fixed.
And depending on how frequently we're updating our software and everyone's updating, everyone's updating their software all the time, we need to be testing those deltas on a regular basis. Um, this, I think is a very effective, uh, and efficient way, uh, to, to spend cybersecurity resources And boy, in our, uh, kind of our geopolitical environment right now. This is really important.
Uh, absolutely topic in Russia and North Korea and Iran, right there, those three countries are, you know, they are spending, they're paying people to spend time to hack all of us. They're serious about it. This is a serious game to them.
It's not just a, uh, a discussion we're having about trying to secure our environments. Right. Very serious.
Yeah. We're not doing this for kicks, you know, we're not doing this because it's a nice to have. We're doing this because attacks are happening all the time to all of us.
You know, I think it's so interesting, um, some of the most recent SEC, um, you know, activity with regards to SolarWinds. Um, and while I don't personally, uh, know that I would go about it in exactly the same way as the SEC is doing, you know, I do have a belief that what they're trying to accomplish is they're trying to put more of an emphasis on the idea that security is really not optional these days. It's really not optional.
It really should not be optional. Um, and I, I, while, uh, there are specifics, uh, about, uh, what's going on, uh, that are not again, necessarily the way that I would personally go about it, um, I do see it being elevated, uh, to a different level of conversation. And for that, I think it's very, very appropriate.
Yeah. And I think that the Biden administration, it made the right move to at least have the SBO m discussion started saying, Hey, if you're gonna do business with the government, you better report to us what open source packages you're, you're consuming, because we may not wanna trust those packages. But I don't find that that kind of data, even though we have it, is being consumed and acted upon.
Yeah. I feel like, I feel like it's still fragmented. It's still not, um, it's out there, but, but, you know, uh, great, you know, SBOs, so far so good.
So what, right. The, the, one of the really interesting things that we have not figured out as an industry is how to effectively communicate technical security posture to each other and even SBO m information to each other in a standardized format. Every organization does it in a different way.
And that means that every time you interact with another organization and any given organization has got to have probably like 75 vendors, you know, larger enterprises are gonna have hundreds, thousands of vendors. Um, but without any sort of standard, um, or, you know, in the case of our industry, actually too many darn standards to choose from. Um, you know, the, the reality of, you know, a person on that security team who's in a vendor risk management role, you know, they've gotta, they've gotta sort of sift through and figure out and interpret, you know, each and every single one.
Um, so there ends up being just a tremendous amount of manual work involved, uh, if folks wanna do it, right? Yes. There is a tremendous amount of toil right now in that, in the, in solving the cybersecurity puzzle, a tremendous amount.
And I think we will face that for the, at least the next five to six years. Even in, you know, my world, you're, you're kind, you're in the, you're in the pen testing business and I'm in the DevOps side. If we think we go back to our Jenkins, um, I, I repeat this many times 'cause it's a good thing to remember.
According to CloudBees, they track about 90 million workflows a month. Uhhuh 90 million. Now, I don't know if those are a duplicated workflows, so let's just say it's, you know, it's 9 million workflows a month, even so, right.
Even there even, yes. It's, it's a humongous number of DevOps pipelines that need to be updated to have security built into it. And this will be a challenge for us because there's a, an extreme amount of toil in being able to achieve that.
So that being offensive one way is to build it in there, right? The other way is maybe we talk about zero trust. So will zero trust get us out of this problem and say, we're gonna start blocking anything that comes from Russia or North Korea or Iran.
We're gonna just block them completely. You know, where are, where are some big wins? Do you have any ideas or have you thought about that?
So I do think that there is a lot of value that comes with zero trust, but I don't think it's possible for zero trust to be fully automated. And what happens is the manual work just gets shifted. Mm-Hmm.
From my perspective, in an ideal zero trust model, you know, the most important stuff has a really big fence around it. And if someone tries to get in some human with their judgment and their opinion is coming in and saying, yes, let them in or no, do not. Um, and that times 9 million ends up being, again, an extraordinary amount of work.
Um, I have a kind of a crazy idea that it would be fun to, uh, share with you, uh, on this, on this, um, session today, which is, I happen to have a garden and I observe the cycles of that garden throughout the season, you know, and there's times when, uh, the seeds are just in the ground and there's times when the plants are growing and there's times when they're blooming and there's times when they're wilting and it's, and it's fall and it's turning to winter, you know? And I actually think that software has this sort of cycle that it goes through as well. And there's a time is not being looked after properly.
Maybe it should be sunset. But what we do is we treat all software all the time, like it's in full bloom. And I think that's actually just not appropriate.
I think it's, I think it's actually just a fundamental misunderstanding, you know, and we work in tech, right? People who don't work in tech, they just assume that everything software works is supposed to work absolutely perfect all the time. And the reality is, some of us know that some software is being paid an incredible amount of attention to, and a lot of other software people aren't paying attention to it.
It's not being updated. All sorts of legacy stuff, all sorts of old integrations. Um, and so I think it would be really interesting, uh, if we had a way to evaluate, is it time to sunset this particular piece of software because it's actually introducing more risk than value.
Really? Interesting. That's a really interesting thought.
You know, what can replace it? What's, what's new out there? And boy, is it hard being from a having a software company, it can be really hard to get customers off of old versions.
Totally. Coming back to your point to say, upgrade your software, please upgrade your software, because we may know there's vulnerabilities out there, but we can't get them get, you know, get folks to update their software because it, it, it may take some time. It may bring down, you may, they, they may need to do a freeze for, you know, an hour and a half.
It may deny service for some period of time, but boy, isn't it important? And I think the better we get at from a software perspective and who does as a, a commercial vendor of software, the better we get at being able to have SaaS environments where we are managing the platform and updating this stuff for them. Yep.
Uh, is ultimately going to be, you know, another way to be offensive in our, our approach to cybersecurity. Because what we're doing, it's not necessarily defensive. What we're doing is we're pushing away.
We are, you know, we are going out after our criminals, right? We're going out after them and saying, no, no, no, no. That's really, it's really, it's really a proactive approach, you know?
Um, I think that businesses have an awful lot of decision making power that affects an organization's security posture. Um, a funny little analogy that a friend of mine used to talk about was, he would say, you know, if you have a toddler and that toddler is running around with a pair of scissors, the best thing to do is to take the scissors out of the toddler's hands. You know?
But how often do businesses and organizations just allow toddlers to run around with scissors? Because there's a lot of Toddlers running with Scissors. There's just a lot, there's a lot of toddlers, scissors, you know, and, and, and, and, and it is a business decision.
And there are gonna be trade offs. That toddler is gonna throw a big temper tantrum, and you're gonna have to deal with it, you know, but you're gonna have mitigated the risk. And so risk.
And so I think this is both the complexity, um, as well as what makes cybersecurity super fun, uh, is all these different trade offs and, and really having a lot of the time no right answer. So when you talk about zero trust, um, just to backtrack a tiny bit, and you talk about all those, these instances, whether it's 90 million or 9 million or whatever, how much of, of all of this we're talking about, I'm just gonna throw it out there. Is AI going to help with 'cause Right.
One person can't say, let this person in block this person. How much, I'm sure companies are already doing it, but I would assume AI is gonna play a huge part because it can do all the massive work, and then a human can evaluate a smaller subset of that, right? As far as being able to manage it, I just, another amazing, you know, application for ai.
Absolutely. I, I completely agree with that concept. I'm actually currently working on a new LinkedIn learning course that I believe we'll launch sometime around August 20, 24.
And this particular topic is about artificial intelligence and application security. And I do think that we have an opportunity for any bit of manual work that we do, whether it has to do with software development, whether it has to do with cybersecurity activities. There's a spectrum of how much can be taken on by ai.
And at each stage of that spectrum, there's gonna be an associated confidence level with how well we think they're gonna do it. It's gonna do it, you know. And so there are gonna be basic, very well, well known, often observed, often repeatable patterns that can be detected.
And AI can even get to a point where it's making this the decision, choosing the next action. You know? But as, as soon as we move farther down that spectrum and things get to be a little more unusual, a little more customized, a little bit more of an edge case, that's where I think we have an opportunity to focus more of the manual effort.
Um, and so I don't happen to think that, um, you know, AI is gonna take all of our jobs. I I do think that it, that it will dramatically change the way in which we work. You know, I said to, um, my 8-year-old and my 11-year-old niece the other day, I said, here's an AI application that I want you to download on your iPad, because I want you to get used to using AI right now.
Right away. I said to them, anytime you would go on Google and ask a Google a question, ask AI instead, because I would love for them to sort of naturally develop this capability for writing AI prompts. Absolutely.
I think it's a really, really good skill to learn how to, you know, chat. GBT is teaching us all that. And I, I keep telling the story.
I, I was waking up with my eyes totally swollen for like, three weeks in a row, and I couldn't figure out what was going on. So I was working, and I just asked, give me a diagnosis for swollen eyes and what's the symptoms? And the first thing that came up was dehydration.
Wow. Yeah. And so I was like, okay, I'm gonna drink 60 ounces of water a day.
And in three days, my eyes stopped being swollen. So I actually used it as for a medical condition. Well, Tracy and I have this conversation all the time because that's, AI terrifies me.
And she's like, AI is the coolest thing ever. It's awesome. So I'm, she's helping me.
Like today I am like this, you know, another example where AI is gonna be really helpful and yes. Another reason humans aren't going away. You know, the whole, the whole concept that it's gonna, you know, there are gonna be some shifts.
There's everything with, you know, with progress comes change, right? There's always gonna be a shift. And that's why people have, we retrain entire groups of people to do different things.
But it's, it's that way with everything. AI isn't any different, but it's cool to, I'm trying to find the good, find the good. I'll tell you what, Say bad this way.
Think about it this way, Jody. We, I was raised with encyclopedias. Well, I'm not Encyclopedia went away.
Encyclopedias went away when the internet became popular. 'cause you could find answers through the internet, but people's jobs didn't. Yeah.
AI is the same thing. It's just a different, we have a different relationship to data, and it's going to be displayed to us in a different way. It's a complete shift, but it's the same thing, right?
It's just, it's the modern day encyclopedia. Well, and Jody, I'll tell you what, there are two fundamental reasons that I believe AI will not and cannot take over all of the work that we do. Thing number one is garbage in, garbage out.
Right? AI works on data. And unless you have an enormous perfect data set, your results are never gonna be exactly right.
Um, our data sets are biased. They're too small. They're, they're wrong, And they're shifting.
Yeah, exactly. Exactly. So that's thing number one.
The other thing is AI requires processes and algorithms. The AI does not know how to choose which process or which algorithm to run unless a human tells them. So, right.
And if, you know, because I work in the area of application security, I think about things like static testing and dynamic testing. I think about the differences between network security vulnerabilities and application security vulnerabilities. And if I have an ai, and that AI is designed to work through a workflow, having to do with finding network security vulnerabilities, and I point that at an app, it's not gonna gimme the results I want.
We need people to dictate what type of process, what type of algorithm. You know, it's like saying, um, uh, you know, chef robot, uh, you know, make me a pumpkin pie, you know? But if you, if you put in the cheesecake recipe, you know you're not gonna get a pumpkin pie.
Um, and so there is, that is An amazing analogy. That is The best analogy ever. Maybe you'll Get a, you'll get a cheesecake, pumpkin pie.
There you go. A Cheesecake. You'll probably get something delicious, but you're not gonna get a pumpkin pie.
You'll not get pumpkin. If there's no pumpkin in the recipe, you're not gonna get a pumpkin pie. That's amazing.
I'm sorry. That was a great analogy. I love that.
I'm gonna steal it. So before we run out of time, this is a question I really love to ask our, um, our guest. Yes.
And tell us what brought you to technology. You're passionate about it as I am, and as most of our, our guests are. You know, how did you get started?
Was there a woman in your life that said, Hey, you need to go into tech. Give us, give us a little bit of insights about your background? It was my dad.
I am the daughter of Chinese immigrants to the United States. When I was a little kid, my dad said, you know what, I'm gonna buy you Mavis speaking, typing software, because my dad was an attorney, you know, and he had a really great secretary who typed on his behalf, you know, but he was one of those one finger typers and said, Caroline, in your lifetime, it's gonna become really valuable for you to learn how to type quickly. And so I learned how to type quickly at the age of, you know, 10 or something.
Uh, and when I was about to go to college, he said to me, Caroline, what do you wanna study in university? And I said, well, I love dance, so I'd love to study dance. And I think psychology is really interesting.
So I'd love to study psychology. And he said, you're gonna study engineering and you're gonna study the hardest engineering at the top school that you can get accepted to. And so I went and I studied electrical engineering and computer science at uc, Berkeley.
And that was that, you know, and I, it was just, it was just the culture of the family that I happened to grow up in. Um, and while, um, you know, I had all sorts of, I would say behavioral and psychological responses to my father's, extremely high expectations of me, um, he did instill a confidence, um, and a kind of like, maybe, I don't know how to do this right now, but I can figure it out, nist about it. Um, and now at this stage in my life, you know, as a mother, and I'm looking at my kiddos and their lives are filled with technology, and I just want the world to be a safe and a happy place.
Mm-Hmm. I just want my kids to be able to use their computers and go on the internet and play their games and be safe and be connected and create without having to worry. That's what I want.
You know? And so, um, I feel so grateful, um, that I'm in this field, uh, and that I get to do this type of work. It's interesting almost all of us that we, none all of us that are in this field, we had a parent or someone who really was forcefully directing us into it.
It wasn't something that we saw that we should do, saw that we should do for naturally, like a little boy might. Right? And it's different now.
We had know somebody say, go for it. It's different now, you know, these days, you know, I don't know exact statistics, but when I studied computer science in college, it was not typical. It's certainly wasn't typical for a woman, but it kind of wasn't typical.
Anyway, you know, these days I think there are so many more computer science graduates than there were at that point in time. Um, and so these things do change. Um, but I am, uh, I'm extremely grateful to my dad, uh, for, for pushing me in that way.
And I hope that the STEM programs that are, you know, starting to really flourish throughout the u the us in particular, uh, can serve as your dad did to you conserve to other young girls who may not have a parent that said, you know, like my mother did, Tracy, you can't draw a straight line. You do math like crazy. You probably should go into some field of engineering.
You probably shouldn't do, you know, history is great, but it's not gonna get you the job you want and go do math. You know what else is crazy though, is we've had these conversations. And Tracy, how many times have we asked this question?
And it started out with, I played an instrument. I, I like to do drama. I like dance.
So much of what we don't acknowledge is that the arts are so important. Um, just as an example, my daughter's now an actress. She went to the Denver School of the Performing Arts here in Denver.
It's a public school open to any kid who auditions and gets in 12 different majors. We also have a STEM school, the School of Science and Technology. Do you know which school is on the, uh, US world and report top schools and gets the best standardized test scores.
The School of the Arts beats the science and technology school every year. 'cause they have art in their curriculum every day. And the kids that just go to the, the science schools don't.
But I hear so many of, so many of the, of you guys who, who we've interviewed have an art artist in them of drawing or dancing or music, and it's so stimulates everybody. And it's so important and needs To be there. I think you, you have to have both, right?
You do have to do, you have to, you, you can't just copy everything. You have to have Both sides of your brain working. You have to have both sides of your brain working.
So I th that, that is why women are so, uh, perfectly kind of positioned to be in technology. And one area that if you're listening and you're a young college student and you're a woman, think about going into cybersecurity. It, it's gonna be, everybody's gonna be pushing it for at least the next five to eight years.
So consider going into cybersecurity or any area and defense. Yeah. Get your, get your daughters in coding classes, our granddaughters middle school.
And she, she loves it. She thinks it's fun and they do it in school. And she, she thinks it's the coolest thing.
Her brother, not so much, but you know, that's okay. Good. That's great.
Exactly. Well, I think we're like right at the end of our window here, but Caroline, thank you so much for being here. I am so excited that, um, you got to join us.
Um, I can't wait to see you at RSA in May. And, um, we just really appreciate you taking the time. We know you're a busy lady and your time is super full, so we appreciate you being here with us today.
Trace, you got anything? No, but thank you Caroline, for a fabulous journey into the world of cybersecurity. This Was so fun.
Thank you both. Great. Well, thank you for being with us.
Hey, everybody, that's, uh, a wrap on today's episode of Techstrong Women. Be sure and stay tuned. There's a lot more great content and programming today, so be sure and watch and we'll see you next time on Techstrong Women.
Bye. Hey guys, this is JJ Manila with Mitch Ashley co-host of CISO Talk where we have engaging bite-sized conversations for current and NextGen CISOs. You know, we have some of the best conversations on CISO talk with some of the greatest talent in security people like Andy Ellis, who talked to us about optimizing security strategies and how to navigate the boardroom.
Lisa Bradley came on and talked about vulnerability management bug bounty programs and why SBOs aren't the solution to all your software security problems. Steve Reynolds was also another great guest, and he talked to us about what not to do when a security incident happens, What not to dos are great, but we also had Eve Mailer and Steve bitten on talking about security, uh, and third party software, SaaS applications, and weaponizing ai. So go ahead and join us for the latest episode of CISO Talk.
You can find us by going to Techstrong TV slash CISO talk. This next interview is Mitchell Ashley, our CTO o and principal researcher at Techstrong Research. Mitch speaks with John Capello of Nasuni and Adrian CIA of Tetra Tech, and they discuss Na Sunni's, uh, NA Sunni's Edge for Amazon Simple Storage S3 availability.
And which by the way, it's a cloud native distributed solution that allows enterprises to accelerate data access and deliver delivery times while ensuring low latency access that is crucial for edge workloads. This is Textron tv. Hi, I have the great pleasure of being joined by a couple gentlemen here.
We're gonna be talking about hybrid cloud network, hybrid storage, you know, as we live in this world of hybrid clouds, how do we manage our data across all those environments? I'm joined by John Capello, who is with Nasuni. I had an announcement recently that we're gonna be discussing, and Adrian cia, and I believe Adrian's a customer writer user of the technology, uh, working with Nasuni, so, uh, with TetraTech.
So, uh, John, why don't you start off, just tell us a little bit about your role in the company and, uh, overview just of what Nasuni is, and then Adrian, if you just mention what you do. Sure. I'll start off with a, just a, a quick intro.
I'm John Cappel, I'm Field C two at Nasuni. Um, I get the pleasure of having to work with a lot of our largest customers. Um, TetraTech being one of our, um, uh, of our biggest customers that really pushes what we do at Nasuni and really takes advantage of a lot of things that we do at Nasuni.
Um, a lot of the innovations that we've been working on recently, um, I've been lucky to be able to engage TetraTech on that. Um, I also work with a lot of our cloud partners, so, um, a key part of our solution is that you have an object storage underneath that, um, you have, um, that you place Nasuni on top of. And so we work with all of our major cloud partners, AWS, Amazon being, um, obviously one of our biggest ones too.
Um, but I'll hand off to Adrian for, um, intros, and then I'll say a little bit about Nasuni after that. Great. Sure.
So, um, I'm Adrian cia, um, with TetraTech, uh, part of the IT system engineering group. Uh, and, um, my main involvement with Nasuni was, um, designing the architecture and, um, doing the project management for the transition from the typical Windows file systems to Nasuni ecosystem. Very good.
Well, tell us about the announcement I think is relative, relative to S3 and AWS environments. Sure, yeah. So, um, uh, just to start, lemme kind of, uh, set the table about like what Nasuni is.
Um, now I'll talk about the fact that we've added S3 as a protocol on top of our massive file system that does a lot of really good things for us. Um, so number one, you know, Nasuni really is a, as Adrian was talking about, kind of the, the evolution of file infrastructure within the enterprise. So think of it as a modern approach to how to store your unstructured data.
Um, up to this point, a lot of customers have been storing it on nas on, um, file servers. So whether it's a Windows file server, whether it's something like, um, you know, a NetApp or an Isilon, um, those are all fantastic data center based solutions for storing data and storing unstructured data. But Nas Sunni came along and we said, what if you could have all the power and the benefits of a nas, but you were backed by some kind of, um, cloud scale, cloud scalable solution.
Um, so what we did was we built a, um, infinitely scalable versioned file system on top of object storage. So you as a customer, you've got access to your AWS account or an Azure account, or Google account, um, or maybe you have a private object store. Um, and we, um, allow you to then create a file system within that object storage within your own, um, your own tenant.
And on top of that, you'll, um, then be able to access your data through a software defined layer of these edges that we call them basically like, um, look, look and peel lot like nas. So for us, you know, we're taking a different approach to how you manage file infrastructure because we have a really, you know, unbelievably scalable foundation to it with an object store. Um, we have built in security and how we actually encrypt the files from edges and move them into the object store.
But we also have a version capability that is, um, really unparalleled in the industry. Um, people talk about restore points or access or, um, you know, backups or, um, uh, you know, uh, snapshots to be able to restore their data. And those are usually hundreds or thousands of different restore points.
We have literally millions to billions of restore points because you can restore files and folders. So security for us is built in, data protection is built into us. And then the fact that it's a, a software defined model where the access points are not the object store, that's not how you get to your data.
You're actually getting it through these edges. These, um, software defined appliances that live as virtual machines, really wherever you can deploy virtual machine. So up to this point, those edges have been speaking files, so it looks like a nas, acts like a na, I can write to it through sips, write to it through NFS.
Um, but what we just announced is we've added a new layer on top of that, a new protocol in which you can get into that, uh, file system, and that's using the S3 protocol. So, um, what you don't see anywhere in the market today is the ability to have this massively scalable file infrastructure, or let's just call it now a global namespace. I can write to it through sips, I can read to it, um, through NFS.
And now that same namespace, without migrating any data, is now available through S3. So in some ways, you can think of what we've developed, not just as a way of adding protocols into your file system or extending out the global namespace, but now up to this point, what you have thought of as almost like a, um, like a data lake, um, an object, um, based architecture for storing unstructured data is now available as caches, wherever you wanna put those caches. So now think of it as the fact that like my S3 based, um, uh, access into a global namespace can now happen through caches that I can put anywhere.
Um, super excited about that. And, um, TetraTech has long been the soon customer, um, uh, uh, Adrian, we've, we've worked together on lots of other projects including, um, a, uh, analytics into your system. Um, I know you guys have been a, um, huge supporter of some of the original data propagation analysis that we've done, as well as, um, what's now, um, uh, but, um, you guys were also there to, um, really help us to think about S3.
And so, um, if you wanna talk a little bit about sort of how S3 works within your environment within TetraTech, or how you're seeing the opportunities for it. Yeah, so, uh, just to, uh, emphasize a couple of points here that you mentioned, John, uh, first of all is, uh, this idea of, um, centralizing, uh, file system, the whole, the entire, uh, data stores for, for the enterprise, uh, without sacrificing the performance. So if you have a centralized file system, uh, you need access, quick access, and that is through the caching devices that you mentioned.
And second biggest, uh, advantage is, uh, the, the backup and especially the restored, uh, everybody e every backup system has a big flaw when it comes to disaster recovery. And, uh, here it was, it's the main advantage because you can restore in minutes or probably hours instead of weeks and, uh, in, in case of a ransomware attack. So those are the two main features that were attractive to us when you started.
And after that, we discovered, uh, more and more features that you continuously add to this ecosystem. Nasuni is a file services applications. Uh, so it's a big distinction.
It's not just a file server file system, it's file services. So services are added all the time. And you mentioned na, Sunni iq, um, a side of the basic, uh, anti, uh, um, virus scan and the ransomware protection and so on.
This, uh, S3 is the newest edition. And, um, it, it, it, it evolves. So it's an evolving system.
It exciting, it keeps up with the times. And, um, recently this S3 that we tested together is, is a, uh, a benefit for it. It may be a niche, uh, type of, uh, enhancement, but it has a future because more and more application will support natively S3.
And this is the, the key part, because uploading data into the cloud from the field, uh, it's a painful, uh, endeavor. Right now. We have, uh, lots of field engineers going in disaster areas and capturing, uh, huge amounts of data later data, uh, images that they have to be uploaded and processed, um, internally.
But right now what they do, they have, uh, they try to use Dropbox, uh, USB drives. Um, it's a multi-step, uh, process that will bring data from the field to the, uh, to in the cloud. So by, by having S3, uh, protocol available, um, it streamlined the whole process.
Uh, it has a consistent, uh, transfer rate based on our testing is not like windows that goes up and down all the time. And, uh, the SIFs that has all the limitations, uh, this is, uh, it, it's a consistent transfer rate and it's very stable. It's, uh, resilient to, uh, internet disruptions.
And, um, it, it, it's all, it, it has a big future into, um, a, a a range of applications. We tested with one of two, and it's based on whatever our clients were required from us. Okay.
So I'm guessing that, uh, part of this, there are a couple things that stood out in what you talked about. One of them was consistency across environments. Right?
Now you're talking about a essentially what a network attached storage like type service in the cloud in, in S3, but also, um, you know, file systems are great for just putting information, but there's a lot of data management practices that go around that, like you talked about, you know, restore points and backup and restore and things like that. What, what were some of the most important things you needed that S3 didn't have now that you've got uni on top of S3? So for us, um, it, it is the, uh, how you move data from the field to the cloud.
Uh, and I'm talking large amount of data, hundreds of gigs, files that are into gigabytes that, uh, you have to process them on the field, put them on connect USB drive mainly, or put them into your Dropbox and go into the office. And two or three step later on, you, you have data where it has to be. So, S3 is, uh, it works.
Um, we, we are testing right now to use VPN less, um, and there are some security issues there, but, uh, nothing that cannot be sold. Uh, and so it'll be a one touch, uh, data movement from what you have on your laptop in the field to, uh, and the SUNY Edge appliance into the cloud and data will be readily available. They can process it right away.
Uh, there are, um, hundreds of, uh, of gigabytes, if not terabytes, of data uploaded daily, that that's the, the biggest problem. So we have lots of contracts with, um, uh, US agencies that goes into the disaster areas, and there are hundreds of people in the field collecting data for insurance and all this kind of, uh, applications Jump in. John, I, I, you know, I, I'm, I wouldn't be the first, I wouldn't be the first person.
I'm guess Adrian isn't the first either, that's worked with the cloud and said, getting data to the cloud to and from the data and then synchronize it in across environments, managing it as a common name space between what's in Amazon AWS and as well as other environments. Um, that, that's, that's a big challenge for data ops groups, if I can use that term, just in general for people in the data business. Yeah, this is, this is one of the exciting things here is that, um, you know, the, um, the, you know, the promise of the cloud is, it's, um, it know it's capacity, it's, you know, performance.
Um, but one of the challenges is trying to work with, you know, a a a company that's been doing, um, you know, kind of amazing engineering work for decades. And a lot of the, you know, current processes don't fit within their, um, uh, within a cloud model. And, and specifically I was thinking about the, the, the lidar and maybe some of the data flow there, which is, um, it's great to be able to upload NS three, but if you know the way that you're gonna be analyzing that means that I need to mount it as a, um, NFS share or mount it as a, um, a SIF share somewhere, and I need to read it because of some other, or some other process, some other application, you know, needs file access.
Like, um, that's a really unique thing that Nasuni can do. Um, so rather than having this complicated as, as you were talking about this data ops flow, which is like upload to one location, you know, process in location, and then transform and move it to another location, and then maybe do some processing, then move it to another location. You know, our, our goal is to simplify that as much as you can.
You know, when we say a global namespace, we really mean it, like it's global, everything can access it. And access is, doesn't just mean like, Hey, I have the ability to, um, you know, send a request from some other location. It's like, I've got the protocol I can access it with.
And that's been the one big thing that's been missing in the cloud, which is I wanna be able to write using whatever modern protocol I, I, I, I need. And S3 is kind of the modern object protocol I wanna be able to read as well, and maybe even write as well using these other file protocols. And, um, Adrian, if I heard what you're saying, like you, you're, you're up doing uploading, um, the LIDAR data, it's gonna get processed.
Is that process necessarily gonna be in S3, using S3 protocol, or could it also be used, um, using the CS protocol for that? Well, there are, uh, specific applications, uh, that, um, uh, that use them for modeling. And, uh, so it is mainly cs, uh, when they use them.
But the biggest problem is, uh, uh, on the operational part, it, there are multiple, uh, locations where data resides. So there office is sitting on files of USB drives and we don't know has been uploaded successfully. Yes or no.
SS is not very reliable on that. It's large amount of data, especially if you go with A VPN. So, um, just moving that data internally in a reliable fashion.
So S3, as I said, it, it's a very, um, predictable mm-hmm. Upload, uh, transfer, um, you, you just start it and you can't forget about it. You don't have to watch it all the time or the, the disconnected, or right now it's on zero mega megabits per secc, uh, kilobits per second, and then so on, and it starts going again.
And oh, how long it'll take, I don't know, maybe an hour, maybe a day. So, um, it, it's very, it, it simplifies the whole upload process, the whole, uh, uh, single source of truth for, for later processing. Yeah, we can't talk about data too long without talking about security.
And, uh, you know, there are, yeah, you know, some security capabilities that are in the cloud. Different cloud providers have, have their own model. Of course, we have ours within our environment.
Uh, how about how does this help with the, the security aspect of managing that in AWS Um, I can, I can take the first, first crack at that. Sure. Um, so, um, for us, we've sort of built a lot of our security model in terms of access control around active directory.
And so when we have a file system that's built on top of the object storage, we are creating all the metadata structures to be able to represent your active directory controls as well. Um, so when we developed, um, this integration into S3, we were then kind of confirmed with the idea of like, wait, there's two different types of access controls that are coming into play here. You've got your ad system, and then you have what is, you know, typically the, the secrets and the access keys that you use for S3 protocol.
So, um, we work hard with our customers to figure out how can we best map these two things together. And what we've come up with is a way in which you can create your own secrets and access keys, and you can put them onto an appliance. And so that appliance will have those secured there.
Um, and then you can map those keys to any part of your global file system, any part of the volume. So you can both put at the top level and then give access to the entire entire volume. Or you can use those keys to be able to map it to lower within the tree, which itself is its own way of being able to, um, map out, uh, security protocols as well.
So we kind of think of it almost the way that like, um, NFS users sometimes work with, um, with SIFs users being able to have like admin access or, or, um, super user access across the tree, and then being able to, to map exports to that. Um, but our, our goal here was to make sure that you, you don't have to re migrate or permission your current global namespace, but we want to be able to have that work in, um, conjunction with the IAM model, the access key model. And so, um, we feel like we come up with a really nice little nice solution here.
It's easy to use, easy to manage, easy to update those, um, uh, those keys. Um, but it doesn't mean that you have to get away from what you're using today, which is, you know, for most, you know, large file infrastructure, it's gonna be, um, active directory. Yeah.
So, um, just to add to that, uh, from our perspective is, uh, aside of what Nasuni is doing in terms of security, our security team, it, it's extremely, uh, diligent into assessing new technology. So anytime we start with a new protocol or a open a, a, a a hole into the firewall, everything goes into a secure area, is mitered for weeks. And, uh, there are reports and security teams give us the blessing at the end of it.
So, uh, it's a, uh, defense in depth, uh, and this is what we try to, regardless of what the vendor is saying, we take our own precautions. So, um, this is pretty much what, uh, how you address security. I'm curious.
Um, so we have to bring up also ai, of course, and people are investing more and more in their, in their, in their products, having AI capabilities, but also in the software that we're developing, uh, including models and machine language algorithms and generative AI as well. But that, that involves pushing a lot of data around, uh, whether it's training, training models, or it's continually feeding new data into models. Um, that data management challenge, transferring that data, you know, models start to drift, they need to be replaced.
All of those kind of things presents a new set of challenges for a lot of data management teams, I would imagine. Talk a little bit about how this might help with that. You wanna start out, John?
Sure. Um, so this is the one I'm really excited about because I think there's, um, a lot of things Nasuni does kind of natively today that, um, you know, ai, um, AI engineers of the future will just start to, or are just gonna start playing with it. Um, and, um, one big one is the fact that we can version at any level of the global namespace and with a lot of granularity over time.
So I like to think of it this way, like if, if, if you think of, um, you know, uh, Adrian's, um, the file systems that, um, Adrian has on us at TetraTech, um, I'm gonna guess I haven't looked at the exact numbers, but I'm gonna guess they have somewhere in the order of a few hundred million restore points. So if we wanted to, we could actually go back to, um, let's say a year and a half ago, we could pick a random date a year and a half ago, and we would say, what if we trained a model off of the dataset that existed on that day? We could do that with NA Sunni.
And to do that, like it really requires you to figure out, well, which part of the tree do I want to be able to train it off of? Maybe it's the projects folder. Maybe it's a specific subset of projects, folders, maybe it's a combination of different projects, folders.
And then we would tell the system, okay, let's restore in a read only way, just say an appliance to that point in time. Well, if you started to train on that day, just that point in time, and then you move forward and you trained a different day, what we've basically allowed is for you to, for you to take a training set instead of starting on day one, you can go back in time and start training your data from as long as you've been on Nasuni. And I think the power of AI, as we've seen today, is the fact that I can keep retraining these models, but almost everyone starts, uh, from like, you know, T zero as like the day I start my training model.
You don't have to do that with na Sunni, start with whenever you start create your Nasuni volume. So now TetraTech is available to them, you know, literally like, you know, um, a thousand times more actual training sets that they can use to train their model just by the fact that we have have this incredibly granular version file system. So that's the one I'm super excited about.
Um, the second thing is the fact that the S3 protocol is kind of a modern protocol. It's the one that works within a lot of these, um, kind of more AI based workflows. If you have a data scientist that is, um, you know, um, is, you know, working off of their Jupyter notebook and wants to test something very quickly, um, boy, it's so much easier to say, okay, well just point it to this S3 endpoint now than, you know, point it to another S3 endpoint.
Some of them do use files and you might wanna mount a, a directory, but, um, we just give you a lot of flexibility for how your AI engineers, your, your, um, ML engineers wanna work today by just giving them a protocol that, um, that works so easily with their tools. So I'd say those are, those are two of the things. Yeah.
So, uh, um, for us at the Tetra Bank right now, the, the main emphasis is to provide more services to our clients. So, uh, traditionally we just gather data, process it, and submit it to the clients. They look at it, they use it for a while, and that's it.
Um, using an AI will allow us to provide more services, give them, uh, the ability to search through my years and years of collaboration and, um, extract more value out of the existing data. So it, it's definitely very an exciting field and, uh, we're just scratching the surface as the surface at this point. So it's a long way to go, but data is there.
And as you mentioned, there are so many restore points that we can go really granular and, uh, be very specific. And I think many organizations are, are starting to learn some new challenges with generative AI and the training and, and, uh, yeah, you know, prompt engineering and some of that. So there's a lot of data that you need to both develop and test those environments before it ever makes it to production as well.
1 point a, but what was that, right? Just to give a kind of ridiculously, but probably common example. Um, are any other things on the announcement that you wanted to make Sure, just, um, a a couple of the, um, the points that I think kind of were made here before, which is, again, it's all part of the existing na sunni system, kinda existing na Sunni volumes.
You can apply that to the, um, S3 protocol to that. Um, one other little thing to touch on, um, because we're a version file system, because we're based off of, uh, um, really the appliances are using XFS underneath, but we're creating our own uni FS file system in the background. We have our own way of storing metadata.
And what that means is that when we implement the S3 protocol, we now allow you to add more metadata than you would just using your standard S3 service. And, um, we're, we've seen customers get excited about that already. Um, I think more and more as we're in this AI space more and more where metadata becomes, um, such a locus of innovation, um, just having the ability to have more than say like, you know, 12 pairs of 12 key value pairs, or more than, you know, 4K of, um, metadata.
It's, we, we've, we've tested well, well beyond that and, um, the system that supports very large metadata structures. So we're excited because now you can, um, think about your S3 target, not just as data, but think of it as being metadata rich as well. Fascinating.
Any other points you wanted to make Adrian? Uh, no, I think we touched on pretty much on anything, uh, that was pertinent for, for this. And, uh, I, I'm looking forward to, uh, I, I'm pretty sure S3 has a future because it's something native to the cloud.
So, uh, we're excited to explore more and more applica, hopefully more and more vendors will have applications that supports S3 natively. Um, so, uh, this is something that, um, we're looking forward to as it is right now. They, you, you need a third party client.
Um, scalability is, I mean, if you want to go to thousands of users, uh, you have to manage something extra, but I'm pretty sure that the future is there for S3. So, uh, looking forward, Well, fantastic. Congratulations on the announcement.
Great to, uh, have this out in market. Where can folks find out a little bit more about this? John?
com/ S3 Edge, in particular, S3 Edge, EDGE. All right, excellent. Well, thank you, gentlemen.
It was great talking with you. It's always, uh, it's fascinating. It's kind of another way the cloud kind of grows up, right?
It's, it, it innovates in its own way, and this is also makes it a little easier for all of us to use all that great storage we have up there in meaningful ways as well. AI being a big important one. So thank you.
Thank you, John. Thank you, Adrian. Thank you.
Thanks to talking again soon. Take care. Thanks.
Bye. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com, home of security bloggers network.
Then we have a, uh, view with vard today. Mike Vard has Michael Stone breaker, chief scientist for DBOS, and he's gonna explain why the time has come to replace Linux and Kubernetes with an operating system based on a database that is much simpler to marry, to manage. I know Michael, he's a great guy.
I don't know if I agree with him on this one, but we'll see. Here's the view of his heart. This is Textron tv.
Hey guys, thanks for the throw. We're here with Michael Stone Breaker, who is now leading an outfit called deboss, and we're talking about the convergence of databases and operating systems and the cloud and functions and all kinds of fun stuff, but they just raised some additional funding, and we're gonna dive in and what all that means, Michael, welcome to show. Thank you, Michael.
Glad to be here. So what is it you guys are trying to do? Because, well, we've had databases and operating systems, you know, tangentially related all these years, but what's changing and how come we need to rethink all this stuff?
Okay, uh, the, well, this, this, uh, deboss project started in 2020 as a research project at MIT and Stanford, and we were motivated by two, two points. The first was, uh, Linux is very elderly. Uh, I, and I first used UNIX on a PDP 1140, uh, one processor.
Uh, this was in 1974, uh, 48 K, not m or G of main memory, and 20 gigabyte, 20 megabytes of disc. Uh, one of the environments in which, uh, devoss runs is the MIT Supercloud, which is 32,000 processors, several terabytes of main memory and many terabytes of secondary storage. So that means the resources that the operating system has to manage has gone up by about six orders of magnitude, uh, you know, in the last 40 ish years.
So, uh, without me saying, another, me saying another word that makes managing operating system state a database problem. So, uh, and Linux, of course, knows nothing about databases and Linux, uh, is elderly. It's having a hard time making forward progress fast, fast.
So, for example, there's no multi-node version of Linux. You've gotta run something like Kubernetes. You get a fairly complicated stack.
So, uh, basically, uh, it's time to send Linux to the home for retired software. Uh, and so that's what we are attempting to do. That's number one.
Uh, and so we have a commercial version of a replacement for Linux, and to, no one's surprised if the managing state is a big problem. You wanna run a database in the kernel, and you wanna basically, uh, run everything on top of a database. So the way to think about deboss is you're familiar with running an operating system on top, uh, underneath a database system.
That's the way everything runs these days. We do exactly the opposite, which we run the operating system on top of, uh, the database. And so operating system services are written in sql, and this puppy is fast enough, and it has much, it has great properties.
Uh, so for example, uh, if the database is the only thing running, uh, then one of the things that the database does is logs events. That's what databases do. So we capture all events and we log them into transactionally, into a data warehouse.
So if you'd like to back up the operating system 10 minutes, uh, just go ahead and do it. So we, uh, we support time travel in the operating system, and if the, uh, and if the database is fast enough to manage operating system state, it's fast enough to run your application state. So you should put your application state in the same database, and then you time travel everything.
So if there's a ransomware attack nine minutes ago, you just back up everything, 10 minutes, single step around the, the intrusion and keep going. So it has wonderful security properties. So that's, that's number one.
We, you know, uh, deboss is an attempt to displace Linux and Kubernetes, uh, and a bunch of other, you know, like if you're running a transactional file system, well, that comes built in because databases are transactional. So it basically simplifies the operating system stack, and that's just plain goodness. mm-Hmm, uh, and it's much more secure.
But then the other thing that we do is, uh, in terms of how do you write applications for this operating system? Well, we could implement pos, uh, which is sort of yesterday's standard. And in the modern, uh, cloud oriented software, the service oriented world, hardly anybody cares about ics.
So we have a new programming environment, uh, which is, uh, transactional. It's, it's basically a TypeScript environment in which everything goes into the database, uh, and it's software as a service. So you structure your application as a collection of modules that are connected in the graph.
Each module is transactional. Each module is durable. Uh, so this creates a very nice programming environment, uh, that's database oriented, transaction oriented, and, uh, and in my opinion, a a great way, a great way to worry about, um, not doing your applications.
So we have two things. We have a new operating system, and we have a new programming environment, uh, that, both of which we're very proud of. Much to unpack there.
Was it not possible to think about just upgrading or modernizing Linux in a way that would add a database capability to it? Or do we need to replace the entire stack? Well, in my, in my opinion, uh, in my opinion, Linux ought to do that.
Uh, but that still leaves it, uh, with mountains of code that are, that's a leaky boat, security wise. Uh, and, uh, that would, that would allow you to, since, since if you upgrade Linux with a database, then, uh, the database is multi-node, uh, and you've now got a bunch of engineering to make Linux multi-node. So it's, it's considerable amount of work.
But in my opinion, uh, my opinion, all future operating systems should have a database at the bottom. And there's a, a good reason for that. I can give you two quick vignettes.
Uh, the first one, which was occurred in 2020, which was when we were just about to start Deboss, and I listened to a talk by Mattes area, who was the founder of Databricks, of course. And mate said, uh, on a routine day, Databricks, which manages Spark instances, the cloud, uh, Databricks manages a million, uh, spark subtasks. And he said, scheduling a million things using conventional technology.
Just, you know, is, is a non-starter. So, uh, Databricks and a bunch of other big, uh, cloud properties, uh, managed, uh, state and managed scheduling out of the database. So Matay, uh, Databricks is already using some of our ideas.
And of course, uh, Matay started whining about, uh, Postgres performance, which is what they were using for scheduling. So I said, we can do better than that. So first, first, uh, thing is that big properties are realizing that you can't do operating system scheduling.
You need to do scheduling, scalable scheduling. Uh, the second thing is, you know, Uber, uh, the guys that, uh, drive you around in the city, uh, they have a programming environment where, uh, they have a collection of schemas. And you, the way you share data is you add columns to this, to this schema.
So everything, all sharing goes through the database, which is exactly what we're advocating. So forward, forward thinking companies are already, you know, using some of our ideas. We just, uh, make it all simple and easy.
In the future, will I also need a, a separate database still from my application? Or is that something I'm gonna invoke directly from the new operating system? Uh, the way deboss works is that we store operating system data in a thing called Foundation db, which is open source.
Uh, our investors said, you've gotta have an open source offering. And so we do. And Foundation DB is not a relational database system, so we thought users would block at putting their data in it.
So we allow you to put your data in any Postgres compliant DBMS, pick your favorite poison. Uh, and from my point of view, all of the big, uh, cloud properties are standardizing on, uh, Postgres wire compatible DBMS. So run, run, uh, cockroach, run situs, run UGA byte, run, RDS run, Postgres, run whatever you want.
Uh, and it's in the kernel. So the answer is your favorite database system should go in the kernel. Uh, and, uh, from our point of view, we're happy to view, we're happy to be user database agnostic.
Uh, and if, if, uh, if it comes to, if it comes to it, we will write a database system at some point if that's turns out to be a, a good business decision. Architecturally, have we kind of painted ourselves into a corner because we have Linux and Kubernetes and all these things and, and stitching them together and, um, managing them adds a level of complexity. And we invest in observability and monitoring tools in the whole stack seems to have gotten fairly weighty over the years.
So, you know, at what point do we kind of, um, have to do something? 'cause the current pressure of the stack is just too much. Uh, that's another reason to move to Debo.
So all that stuff goes away. So if I'm managing the environment and all that information is in the database, then am I just launching a, uh, a SQL query to surface that? Or, because today I have to kind of use various querying tools, and a lot of people don't know exactly how to make that, uh, work because, well, they're all written in these kind of proprietary formats.
Exactly. So you could give my pitch, excuse me. So all operating system state is in the database.
So if you wanna know anything about what's happening, you just run a SQL query. So if you wanna know how many users are chewing up space, only counting us, uh, files that are bigger than a hundred gigabytes, that's just a SQL query. 'cause, uh, remember the way deboss works is we have, we have a message system.
It, it's written in sql. So there is a message table with a sender, a receiver, and a payload. And to send a message, you do a SQL insert into this table.
Uh, and that table is partition. So it ends up, uh, the, the bites in your message end up at the home node of the receiver who reads a message by doing a SQL query. So that's all you have to do.
And you can, since the message system is a table, anybody can query it in sequel. Uh, and if you wanna, if you wanna say, um, uh, if you have a suspected bad actor and you wanna say, tell me everybody who's sent the bad actor a message or received a message from the bad actor in the last two hours just to SQL query, whereas today, uh, it's essentially impossible to find that information. You talked about the all of this.
Um, do you think that they'll be involved in this decision making process or this transition, or are they gonna exert a lot of influence on that? Or is it more like a, a, a downstream benefit that they'll appreciate one day, but today they're not that involved? Well, here's my point of view, which is everyone is moving everything they can to the cloud as quickly as they can.
And so one way to deal with the cloud is to do a lift and shift. Uh, and if you do that, then the successor in your job will inherit all the problems you currently have. So, in my opinion, you have a once in a generation opportunity to make your software system better.
Uh, and so adventuresome enterprises, I think, are willing to refactor, rewrite, uh, put green, uh, do green fields in a better way. So our point of view is we are appealing, uh, primarily to, as a deboss is only, uh, runs on the cloud. Uh, we will offer an on-prem solution if we have to at some point, but the cloud is where things are going.
Uh, and on the cloud, you are highly encouraged to run software as a service. Uh, all you have to do is look at Amazon pricing, uh, to figure that out. And so if you're gonna move to a software ser as a service environment on the cloud, uh, it's just natural to run our stuff, uh, rather, and if you're gonna refactor what you're currently running, uh, you might as well refactor it into us rather than into something else.
Mm-Hmm. So, uh, we, we are, we are planning on, uh, marketing to adventure some enterprises as they move to the cloud. Also, the three letter agencies, uh, love our security story.
Mm-Hmm. Uh, and also, uh, financial services folks, uh, love us for a different reason, uh, which is, are you familiar with the term Once and only once? Um, it's been a while, but yeah, I seem to remember hearing that a, a while back.
So just for example, if, if I want to, uh, give you a hundred dollars, uh, your, your finances are presumably in a different system than mine. Uh, and this application was motivated by a large, uh, northeast regional bank who we talked to at, at some length, and are plan, they are planning to be an early, uh, deboss user. So the way they, the way they do it is they, they debit my account, then they send a message to your system, they increment your system, they, uh, get a return message back to my system.
And then you want to commit the transaction. And only then, uh, and of course your system and my system, uh, in the banking world are unlikely to implement xa, meaning they're unlikely to implement distributed transactions, which is what you need to do once and only once, which is this, this whole, this whole saga either op, you know, uh, runs to completion or it looks like it never happened. So because we run the message system, uh, we can do once and only once, uh, banking transactions, and that's very attractive to this particular regional bank.
Uh, they figure that, uh, somewhere between a third and a half of their application code is making sure that this stuff works. Uh, and so distributed transactions are not for the faint of heart. And if you do them an application code, their brittle, there's a lot of code they tend to screw up.
So this regional bank would love to get rid of all that. Uh, and so they're, they are incented to move to a new environment by the ability to, to do once and only once, uh, in a much cleaner way. Hmm.
I'm suddenly having memories of misadventures with two-phase commits and all that fun stuff. Right? Exactly.
All right. So today, everywhere you turn around, there's these massive investments in ai. Um, and a lot of that is in the realm of AI ops.
Um, are we investing in AI as it relates to IT operations to compensate for the complexity? But maybe we should be going the other way and just reducing the complexity, Uh, to the ex. Uh, I think, uh, you said it perfectly about 10 minutes ago, which is the current operating environment that people are trying to manage is ridiculously complicated.
Uh, you need a Linux administrator, you need a Kubernetes administrator, you've gotta make sure that, uh, your Linux settings and your Kubernetes system, uh, settings don't conflict. Uh, you may be running a transactional file system, you may be running a separate high availability system. Uh, you're probably investing in two or three, uh, security oriented monitoring products.
Getting all that stuff to work correctly is daunting. So we promise a much simpler life that will make, uh, that'll make operations a great deal simpler. Uh, and, um, uh, from my point of view, that's totally separate from chat GPT and other large language models, which are basically decision support like things.
Uh, and we are not particularly focused on decision support since they are, they are often don't care about transactions, don't care about high availability, don't care about recovery and so forth. All right, folks. You heard it here.
The principle is still the same. Right? Keep it simple, stupid, and you have a happier life.
Hey Michael, thanks for being on the show. Oh, thanks for your time, Michael. Alright.
And back to you guys in the studio. All right. We got a chock full lineup today on Text Trunk tv.
I hope you enjoyed it all. Uh, we'll be back tomorrow with more, but until then, this is Alan Shimel for Techstrong tv. Be safe.
Be strong, be tech strong.